Cross-site scripting (XSS) vulnerability in admin/home/homepage/search in the web app in Adobe Connect before 9.4 allows remote attackers to inject arbitrary web script or HTML via the query parameter.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0343
Reference (s):
- BUGTRAQ:20150611 XSS vulnerability Adobe Connect 9.3 (CVE-2015-0343 )
- URL: http://seclists.org/bugtraq/2015/Jun/61
- https://helpx.adobe.com/adobe-connect/release-note/connect-94-release-notes.html#Issues%20Resolved
- FULLDISC:20150611 XSS vulnerability Adobe Connect 9.3 (CVE-2015-0343 )
- URL: http://seclists.org/fulldisclosure/2015/Jun/35