Impact
Adobe Experience Manager is vulnerable to a stored Cross‑Site Scripting (XSS) flaw where a low‑privileged attacker can inject malicious JavaScript into form fields that are subsequently rendered to other users. Attackers can exploit the flaw by submitting crafted content in vulnerable fields, and the malicious script will execute in the victim’s browser when they view the page containing the injected content. Because the vulnerability changes scope, an attacker who initially had limited access could elevate their impact to affect other users or system components that render the stored content.
Affected Systems
Adobe Experience Manager 6.5, Adobe Experience Manager 6.5 LTS, and Adobe Experience Manager as a Cloud Service are affected. No specific sub‑versions are listed; anyone running these products should verify if the flaw applies to their installation.
Risk and Exploitability
With a CVSS score of 5.4, the vulnerability has moderate severity. The EPSS score is not available, and the vulnerability is not cataloged in CISA’s KEV list. The attack vector is inferred to be local or remote depending on the attacker’s ability to submit content to the vulnerable form; the exploit requires the attacker to be able to create or modify content. Once injected, the script runs in the victim’s browser, leading to data theft, credential compromise, or further attacks. Because it is a stored XSS, multiple users may be impacted, and the compromised content can persist across sessions, making mitigation important.
OpenCVE Enrichment