CVE-2025-46982
published 2025-06-10CVE-2025-46982: Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged…
PriorityP428medium5.4CVSS 3.1
AVNACLPRLUIRSCCLILAN
EPSS
0.28%
19.8th percentile
Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | adobe_experience_manager | <= 6.5.22 | — |
| adobe | experience_manager | < 6.5.23.0 | 6.5.23.0 |
| adobe | experience_manager | < 2025.5.0 | 2025.5.0 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Suricata
ET WEB_SPECIFIC_APPS Next.js Cached Server Response (CVE-2024-46982)
suricata·2025-01-27·CVSS 7.5
CVE-2024-46982 [HIGH] ET WEB_SPECIFIC_APPS Next.js Cached Server Response (CVE-2024-46982)
ET WEB_SPECIFIC_APPS Next.js Cached Server Response (CVE-2024-46982)
Rule: alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ET WEB_SPECIFIC_APPS Next.js Cached Server Response (CVE-2024-46982)"; flow:established,to_client; flowbits:isset,ET.NextJS.CVE-2024-46982; http.header; to_lowercase; content:"cache-control|3a 20|s-maxage=1, stale-while-revalidate"; fast_pattern; reference:url,zhero-web-sec.github.io/research-and-things/nextjs-cache-and-chains-the-stale-elixir; reference:cve,2024-46982; classtype:web-application-attack; sid:2059711; rev:1; metadata:attack_target Server, tls_state TLSDecrypt, created_at 2025_01_27, cve CVE_2024_46982, deployment Perimeter, deployment Internal, deployment SSLDecrypt, confidence High, signature_severity Major, tag Exploit, updated_at 2025_01_27, mitr
Suricata
ET WEB_SPECIFIC_APPS Next.js Forced Caching via x-now-route-matches HTTP Header (CVE-2024-46982)
suricata·2025-01-27·CVSS 7.5
CVE-2024-46982 [HIGH] ET WEB_SPECIFIC_APPS Next.js Forced Caching via x-now-route-matches HTTP Header (CVE-2024-46982)
ET WEB_SPECIFIC_APPS Next.js Forced Caching via x-now-route-matches HTTP Header (CVE-2024-46982)
Rule: alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET WEB_SPECIFIC_APPS Next.js Forced Caching via x-now-route-matches HTTP Header (CVE-2024-46982)"; flow:established,to_server; flowbits:set,ET.NextJS.CVE-2024-46982; flowbits:noalert; http.header; content:"x-now-route-matches|3a 20|1"; fast_pattern; reference:url,zhero-web-sec.github.io/research-and-things/nextjs-cache-and-chains-the-stale-elixir; reference:cve,2024-46982; classtype:web-application-attack; sid:2059710; rev:1; metadata:attack_target Server, tls_state TLSDecrypt, created_at 2025_01_27, cve CVE_2024_46982, deployment Perimeter, deployment Internal, deployment SSLDecrypt, confidence High, signature_severity Major, tag Explo
No public exploits indexed.
No writeups or analysis indexed.
2025-06-10
Published