nozeroinsect

nozeroinsect

CVE – 2019 – 16469 – Adobe Experience Manager expression language injection vulnerability

Description Adobe Experience Manager versions 6.5, 6.4, 6.3, 6.2, 6.1, and 6.0 has an expression language injection vulnerability. Successful exploitation could lead to sensitive information disclosure. Exploitation The vulnerable endpoint is the following: https://<BASE_URL>/mnt/overlay/dam/gui/content/assets/metadataeditor.external.html The vulnerable parameter is the item…