CVE-2021-21085

Adobe Connect version 11.0.7 (and earlier) is affected by an Input Validation vulnerability in the export feature. An attacker could exploit this vulnerability by injecting a payload into an online event form and achieve code execution if the victim exports and opens the data on their local machine.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:adobe:connect:*:*:*:*:*:*:*:*

History

28 Jun 2021, 13:15

Type Values Removed Values Added
Summary Adobe Connect version 11.0.7 (and earlier) is affected by an Input Validation vulnerability in the export feature. An attacker could exploit this vulnerability by injecting a payload into the registration form and achieve arbitrary code execution in the context of the admin account. Adobe Connect version 11.0.7 (and earlier) is affected by an Input Validation vulnerability in the export feature. An attacker could exploit this vulnerability by injecting a payload into an online event form and achieve code execution if the victim exports and opens the data on their local machine.

11 Jun 2021, 18:15

Type Values Removed Values Added
Summary Adobe Connect version 11.0.7 (and earlier) is affected by an Input Validation vulnerability in the export feature. An attacker could exploit this vulnerability by injecting a payload into an online event form and achieve code execution if the victim exports and opens the data on their local machine. Adobe Connect version 11.0.7 (and earlier) is affected by an Input Validation vulnerability in the export feature. An attacker could exploit this vulnerability by injecting a payload into the registration form and achieve arbitrary code execution in the context of the admin account.

27 May 2021, 01:15

Type Values Removed Values Added
Summary Adobe Connect version 11.0.7 (and earlier) is affected by an Input Validation vulnerability in the export feature. An attacker could exploit this vulnerability by injecting a payload into the registration form and achieve arbitrary code execution in the context of the admin account. Adobe Connect version 11.0.7 (and earlier) is affected by an Input Validation vulnerability in the export feature. An attacker could exploit this vulnerability by injecting a payload into an online event form and achieve code execution if the victim exports and opens the data on their local machine.

18 Mar 2021, 13:45

Type Values Removed Values Added
CPE cpe:2.3:a:adobe:connect:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : 7.1
v2 : 6.8
v3 : 7.8
References (MISC) https://helpx.adobe.com/security/products/connect/apsb21-19.html - (MISC) https://helpx.adobe.com/security/products/connect/apsb21-19.html - Vendor Advisory

12 Mar 2021, 19:20

Type Values Removed Values Added
New CVE

Information

Published : 2021-03-12 19:15

Updated : 2023-12-10 13:41


NVD link : CVE-2021-21085

Mitre link : CVE-2021-21085

CVE.ORG link : CVE-2021-21085


JSON object : View

Products Affected

adobe

  • connect
CWE
CWE-20

Improper Input Validation