cvedb.io
CVE-2022-28820
MEDIUM · CVSS 6.1
EPSS exploitation probability: 0%
Published 2022-04-21T19:15:09.053 · Last modified 2026-06-17T04:39:08.073

Summary

ACS Commons version 5.1.x (and earlier) suffers from a Reflected Cross-site Scripting (XSS) vulnerability in /apps/acs-commons/content/page-compare.html endpoint via the a and b GET parameters. User input submitted via these parameters is not validated or sanitised. An attacker must provide a link to someone with access to AEM Author, and could potentially exploit this vulnerability to inject malicious JavaScript content into vulnerable form fields and execute it within the context of the victim's browser. The exploitation of this issue requires user interaction in order to be successful.

Affected products

adobe — acs_aem_commons

Does this affect you?

Add your gear to cvedb and we'll alert you only when adobe ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.