PatchSiren cyber security CVE debrief
CVE-2023-4663 Adobe CVE debrief
CVE-2023-4663 describes a reflected cross-site scripting issue in Connect, with the supplied NVD data indicating vulnerable Adobe Connect versions before 9. The flaw is classified as a script-related HTML tag neutralization problem (CWE-79/CWE-80). Because the attack vector is network-based and requires user interaction, it is more likely to be used against targeted users than as a fully automated wormable issue.
- Vendor
- Adobe
- Product
- Connect
- CVSS
- MEDIUM 6.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2023-09-15
- Original CVE updated
- 2026-05-21
- Advisory published
- 2023-09-15
- Advisory updated
- 2026-05-21
Who should care
Administrators and security teams responsible for Connect deployments should care, especially if users access public-facing pages or links that reflect request input. End users may also be affected if they are likely to click crafted links to affected pages.
Technical summary
The supplied record maps CVE-2023-4663 to a reflected XSS condition in Connect. NVD lists the vulnerable CPE as adobe:connect:* with an upper bound before 9.0, and the CVSS vector is CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N. That means the issue is remotely reachable, does not require authentication, but does require a victim to interact with a crafted request or link. The effect is script execution in the browser context of the affected application, with limited confidentiality and integrity impact and no availability impact in the supplied scoring.
Defensive priority
Medium
Recommended defensive actions
- Upgrade Connect to a version at or above the first fixed release indicated by the vendor/NVD boundary (version 9.0 or later, per the supplied record).
- Review any pages or parameters that reflect user-controlled input into HTML and ensure output encoding is applied consistently.
- Validate that temporary mitigations, such as web application filtering or strict input handling at the edge, do not break legitimate workflows.
- Prioritize user-facing entry points, invitation links, and login or redirect flows that can carry reflected parameters.
- Monitor for reports of suspicious links or browser-side script execution attempts against the application.
Evidence notes
The supplied official sources show CVE publication on 2023-09-15 and a later NVD modification on 2026-05-21. NVD identifies the weakness as CWE-79 with a secondary CWE-80 mapping in a third-party advisory, and the vulnerable CPE is adobe:connect:* with versionEndExcluding 9.0. The record is not marked as KEV in the supplied data.
Sources and references
Verified primary and authoritative sources
-
CVE-2023-4663 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2023-4663
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2023-4663 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2023-4663
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-23-0535
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://www.usom.gov.tr/bildirim/tr-23-0535
[email protected] - Third Party Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.