Adobe Patches 36 Vulnerabilities, Including Critical Flaws in Connect and AEM Forms
Adobe has released patches for 36 vulnerabilities across several of its products, including critical-severity flaws in Adobe Connect and Experience Manager (AEM) Forms. The Adobe Connect update addresses nine security defects, six of which are critical and could lead to arbitrary code execution and privilege escalation. These critical issues include SQL injection, cross-site scripting (XSS), and improper input validation flaws. Additionally, high-severity path traversal, improper certificate validation, and XSS weaknesses were resolved. For AEM Forms, Adobe patched six vulnerabilities, with three critical-severity flaws that could result in code execution and privilege escalation, stemming from incorrect authorization, improper input validation, and server-side request forgery (SSRF). High-severity SSRF, XSS, and cross-site request forgery (CSRF) bugs were also fixed in AEM Forms. Adobe also issued fixes for high- and medium-severity vulnerabilities in InDesign, Content Credentials SDK, Bridge, Substance 3...