Impact
Adobe Experience Manager is affected by a stored Cross‑Site Scripting vulnerability that can be exploited by a low‑privileged attacker to inject malicious JavaScript into vulnerable form fields. When a victim views the affected page, the injected script executes in the victim’s browser, potentially allowing cookie theft, session hijacking, defacement, or execution of arbitrary JavaScript in the context of the application. The vulnerability’s scope is altered, implying the attacker could gain additional privileges beyond the initial low‑privilege level.
Affected Systems
The affected products are Adobe Experience Manager 6.5, the 6.5 LTS release, and the Adobe Experience Manager as a Cloud Service offering, as identified by the CNA. No other vendors or product lines are listed, and version details beyond the product name are not provided.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate severity. Exploit probability is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting there is no known large‑scale exploitation. Attackers would typically need access to a form or permission to create or edit content within AEM to inject malicious payloads. Once injected, the script runs with the victim’s browser privileges, potentially compromising confidential information and affecting the integrity of the user session. The lack of a high EPSS score or KEV listing does not preclude exploitation, especially in environments where end‑users can submit content without stringent validation.
OpenCVE Enrichment