Impact
Adobe Experience Manager has a stored cross‑site scripting vulnerability that allows a low‑privileged attacker to inject malicious JavaScript into form fields. When the victim visits the affected page, the browser executes the injected script, which can lead to session hijacking, data theft, or other malicious activity. The weakness is identified as CWE‑79 and the scope is changed, indicating that the exploited flaw can affect the overall system beyond the initial input.
Affected Systems
All instances of Adobe Experience Manager 6.5, Adobe Experience Manager 6.5 LTS, and Adobe Experience Manager as a Cloud Service are potentially impacted. Specific affected versions are not enumerated in the advisory, so any build of these products may contain the flaw until an update is applied.
Risk and Exploitability
The CVSS score of 5.4 places this vulnerability in the medium‑to‑high range. Although EPSS data is not available, the stored nature of the flaw and the requirement for only low‑privileged access mean it is likely to be exploitable by attackers who can submit content. The vulnerability is not listed in CISA’s KEV catalog, but it still poses a notable risk to organizations using the affected products. Attackers generally must have web access to submit malicious form data and rely on unsuspecting users visiting the resulting pages.
OpenCVE Enrichment