Impact
A low‑privileged attacker may insert malicious JavaScript into vulnerable form fields of Adobe Experience Manager. The script is stored and later executed in any victim’s browser when they view the page that contains the input field. This can lead to theft of session data, credential compromise, or further manipulation of the affected system. The vulnerability’s scope is changed, indicating that the attacker can affect the system on the same level as the authenticated user who submitted the input.
Affected Systems
Adobe Experience Manager versions 6.5 and 6.5 LTS, as well as the Cloud Service offering. The vulnerability is present in all forms and components that allow user input without proper sanitization.
Risk and Exploitability
The CVSS score of 5.4 categorizes this issue as medium severity. The EPSS score is not available, and the vulnerability is not listed in CISA KEV, suggesting that active exploitation at this time is not documented. The likely attack vector involves submitting a crafted payload in a form field that is later rendered on a page viewed by other users. Because the vulnerability is stored, the attack can persist across sessions, making the risk significant for organisations that rely heavily on user‑generated content.
OpenCVE Enrichment