Impact
Adobe Experience Manager versions FP11.4 and earlier contain a stored Cross‑Site Scripting flaw. A low‑privileged attacker can inject malicious JavaScript into form fields, which will run in a victim’s browser when the page is viewed. The affected code changes scope, allowing the bug to affect users beyond the immediate attacker, and can lead to data theft, session hijacking, or further web‑based attacks.
Affected Systems
The flaw exists in Adobe Experience Manager, versions FP11.4 and earlier. These releases include the Experience Manager product from Adobe and are used in web content management and digital experience applications.
Risk and Exploitability
The CVSS score is 5.4 and the EPSS score is below 1 %, indicating a moderate severity with a low probability of widespread exploitation. It is not listed in the CISA KEV catalog. The vulnerability is exploitable by any user that can submit data to the vulnerable form fields, implying a likely attack vector of web‑based form submission or manipulation. Because the scope is changed, an attacker could also impact users that view content rendered from those fields.
OpenCVE Enrichment
EUVD