Impact
Adobe Experience Manager is affected by a stored Cross‑Site Scripting vulnerability that allows a low‑privileged attacker to inject malicious scripts into vulnerable form fields. When a victim accesses the page containing the stored payload, the scripts can execute in the victim’s browser. This flaw is identified as CWE‑79 and can potentially lead to defacement, credential theft, or other malicious actions performed in the victim’s session.
Affected Systems
Affected products include Adobe Experience Manager 6.5, Adobe Experience Manager 6.5 LTS, and Adobe Experience Manager as a Cloud Service. The CVE description does not list specific patch versions, but all instances of the listed products are considered vulnerable until the fix is applied.
Risk and Exploitability
With a CVSS score of 5.4, the vulnerability carries a medium severity rating. The lack of an EPSS score suggests low publicly known exploitation activity, and the vulnerability is not listed in the CISA KEV catalog. However, because the flaw changes scope, a compromised low‑privileged user can affect all authenticated users on the site. The attack vector is inferred to be via entry into a vulnerable form field, after which the malicious JavaScript runs in the context of any user who loads the affected page.
OpenCVE Enrichment