Impact
Adobe Experience Manager is affected by a stored Cross‑Site Scripting (XSS) vulnerability that can be exploited by a low‑privileged attacker to inject malicious scripts into vulnerable form fields. When a victim visits a page containing the malicious data, the browser will execute the injected JavaScript, potentially allowing the attacker to intercept credentials or hijack the session. The described vulnerability changes the security scope and provides a persistent scripting vector that is not limited to a single user session.
Affected Systems
The vulnerability affects Adobe Experience Manager 6.5, Adobe Experience Manager 6.5 LTS, and Adobe Experience Manager as a Cloud Service. Version information for the fixed releases is not currently listed, so any deployment of these products prior to the release of an available patch is susceptible.
Risk and Exploitability
The CVSS base score of 5.4 indicates a moderate severity. The EPSS score is reported as <1%, suggesting a low probability of exploitation at present. However, the attack surface is visible to any user who can submit data to the vulnerable form fields, and the payload can persist in the system until removed. Because the exploitation does not require privileged access, attackers who can submit a crafted form may achieve persistent cross‑site scripting that executes on each viewer's browser. The vulnerability is not listed in the CISA KEV catalog at this time.
OpenCVE Enrichment