Adobe Experience Manager Forms versions 6.2 and earlier, LiveCycle 11.0.1, LiveCycle 10.0.4 have an input validation issue in the PMAdmin module that could be used in cross-site scripting attacks.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-6934
Reference (s):
- BID:94867
- URL: http://www.securityfocus.com/bid/94867
- https://helpx.adobe.com/security/products/aem-forms/apsb16-40.html
- SECTRACK:1037465
- URL: http://www.securitytracker.com/id/1037465