Impact
Adobe Experience Manager is vulnerable to stored XSS where a low‑privileged attacker can insert malicious JavaScript into form fields. The injected script executes when any user loads the page that includes the compromised field, allowing the attacker to hijack user sessions, deface content, or exfiltrate data. This vulnerability changes the scope of the affected application, affecting all users who view the compromised content.
Affected Systems
Affected are Adobe Experience Manager 6.5, its long‑term support version, and the cloud‑service deployment. Attackers with access to any form field in these versions can insert the malicious payload. No specific version numbers are listed beyond the major releases, so all builds within these lines are potentially impacted.
Risk and Exploitability
The CVSS score of 5.4 indicates a moderate impact. The EPSS score is not available, which provides no direct indication of current exploitation frequency, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack path is via unauthenticated or low‑privilege submission through exposed form inputs, after which a victim later loads the stored value. Because the outcome relies on victim interaction, widespread automated exploitation is less likely, but the impact on individual users remains significant if the user trusts the impacted domain.
OpenCVE Enrichment