Impact
Adobe Experience Manager is vulnerable to a stored cross‑site scripting flaw. A low‑privileged attacker can inject malicious JavaScript into vulnerable form fields, causing it to execute when a victim visits the affected page. The weakness is classified as CWE‑79 and is verified to change the scope of the attack.
Affected Systems
Adobe Experience Manager version 6.5, 6.5 LTS, and the Adobe Experience Manager as a Cloud Service are affected. Any installation of these versions that exposes the vulnerable form fields to a low‑privileged attacker is at risk.
Risk and Exploitability
The CVSS score is 5.4, indicating moderate severity, and an EPSS score is not available while the vulnerability is not listed in CISA’s KEV catalog. Because the flaw allows script injection through form input, the likely attack vector involves a low‑privileged user submitting crafted data that is then stored and rendered on a page viewed by other users. Exploitation requires the attacker to have write access to the form fields but not necessarily privileged network or system access.
OpenCVE Enrichment