Impact
The vulnerability is a stored XSS flaw in Adobe Experience Manager that lets an attacker who has low privileges inject malicious JavaScript into form fields. When a victim later opens the affected page, the injected script runs in the victim’s browser context, potentially compromising the victim’s data, hijacking sessions, or executing further attacks. The flaw involves a change of scope, indicating that it can affect the entire web application beyond the originally affected component.
Affected Systems
Adobe Experience Manager versions 6.5, 6.5 LTS, and the Cloud Service are vulnerable. Any deployment that includes these editions must be checked for the presence of the affected form fields.
Risk and Exploitability
The CVSS score of 5.4 classifies the vulnerability as medium severity, and the EPSS score is not available. The vulnerability is not listed in the CISA KEV catalog. An attacker can exploit the flaw by submitting crafted input to the vulnerable form, which is then stored and reflected in pages viewed by other users. Based on the description, it is inferred that the attacker would initially use a low‑privileged account to submit the malicious input. Because the flaw requires only low privileges to inject malicious content, the risk to users is significant, but no widespread exploitation information is reported at this time.
OpenCVE Enrichment