Web Hack List

Collected research

How we got persistent XSS on every AEM cloud site, thrice

Describes three routes to persistent cross-site scripting across Adobe Experience Manager Cloud deployments. The chains abuse shared authoring and delivery behavior, stored content, and insufficient sanitization to make attacker-controlled markup execute on customer sites.

Record

Researcher
Adam Kues

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Adam Kues, first published at the original source. Preserved copies are kept so the citation survives its host.