CVE-2025-1484 – Adobe Asset Suite Cross-Site Scripting

The following table lists the changes that have been made to the
CVE-2025-1484 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.

  • New CVE Received
    by [email protected]

    May. 30, 2025

    Action Type Old Value New Value
    Added Description A vulnerability exists in the media upload component of the Asset
    Suite versions listed below. If successfully exploited an attacker
    could impact the confidentiality or integrity of the system. An attacker can use this vulnerability to construct a request that will
    cause JavaScript code supplied by the attacker to execute within
    the user’s browser in the context of that user’s session with the
    application.
    Added CVSS V4.0 AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
    Added CVSS V3.1 AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
    Added CWE CWE-184
    Added Reference https://publisher.hitachienergy.com/preview?DocumentID=8DBD000212&LanguageCode=en&DocumentPartId=&Action=Launch
Share the Post:

Related Posts