Severity
6.5MEDIUM
EPSS
3.4%
top 12.65%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 26
Latest updateMay 24

Description

Adobe Photoshop CC versions 19.1.8 and earlier and 20.0.5 and earlier have an out of bound read vulnerability. Successful exploitation could lead to memory leak.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages2 packages

NVDadobe/photoshop_cc20.020.0.5+1
CVEListV5adobe/adobe_photoshop_cc<=19.1.8 and <=20.0.5

🔴Vulnerability Details

2
GHSA
GHSA-979p-jg98-vpvh: Adobe Photoshop CC versions 192022-05-24
CVEList
CVE-2019-8000: Adobe Photoshop CC versions 192019-08-26

💥Exploits & PoCs

11
Exploit-DB
Django < 3.0 < 2.2 < 1.11 - Account Hijack2019-12-24
Exploit-DB
oXygen XML Editor 21.1.1 - XML External Entity Injection2019-11-14
Exploit-DB
Ajenti 2.1.31 - Remote Code Execution2019-10-14
Exploit-DB
thesystem 1.0 - Cross-Site Scripting2019-09-30
Exploit-DB
TheSystem 1.0 - Command Injection2019-09-30

📋Vendor Advisories

1
Citrix
CVE-2019-13608: Citrix StoreFront Server before 1903, 7.15 LTSR before CU4 (3.12.4000), and 7.6 LTSR before CU8 (3.0.8000) allows XXE attacks.2019-08-29
CVE-2019-8000 (MEDIUM CVSS 6.5) | Adobe Photoshop CC versions 19.1.8 | cvebase.io