CVE-2022-35697
AEM WCM Core Components CVG Image vulnerable to Reflected Cross-site Scripting
5.4
MEDIUM
CVSS 3.1
EPSS 0.40%
Description
Core Components version 2.20.6 (and earlier) suffer from a reflected cross-site scripting (XSS) vulnerability in `AdaptiveImageServlet` via SVG images. An attacker with author access can upload a special crafted SVG image (including a malicious Javascript) and obtain a link that, when loaded by another authenticated users, will execute the malicious script and gain access to other user's session. The issue has been resolved in 2.20.8. There are currently no known workarounds.
How to fix CVE-2022-35697
To remediate CVE-2022-35697, upgrade the affected package to a fixed version below.
- —upgrade to 2.20.8 or later
Is CVE-2022-35697 being exploited?
Low — EPSS is 0.4%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 2.20.8
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM5.4 | CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |