Situatie
Adobe released critical security updates in June for multiple products:
-
225 vulnerabilities in Adobe Experience Manager (AEM)
-
CVE-2025-47110 in Adobe Commerce (Magento) – a high-risk reflected XSS vulnerability (CVSS 9.1) that can lead to client-side code execution.
Risks:
-
XSS can allow attackers to hijack sessions, modify content, or launch phishing attacks
-
In unpatched Magento stores, attackers can exploit poor sanitization in URL parameters to inject malicious scripts.
Recommendations:
-
Update AEM and Commerce to latest versions immediately
-
Use a Web Application Firewall (WAF) to block known exploit vectors
-
Perform regular scans and code reviews for custom plugins or templates.
Leave A Comment?