Impact
Adobe Experience Manager is affected by a stored cross‑site scripting vulnerability that allows a low‑privileged attacker to inject malicious scripts into form fields. If the victim visits a page that renders the compromised field, the injected JavaScript executes in the victim’s browser. The flaw is a stored XSS weakness (CWE‑79) that can be abused to compromise user confidentiality and potentially deliver further attack payloads. The vulnerability includes a scope change, indicating that the impact may extend beyond the originator of the request.
Affected Systems
Affected products include Adobe Experience Manager 6.5, Adobe Experience Manager 6.5 LTS, and Adobe Experience Manager as a Cloud Service. Specific version details are not provided beyond the product families; the information indicates that any deployment of these product lines is potentially vulnerable.
Risk and Exploitability
The CVSS score of 5.4 classifies the vulnerability as moderate severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Exploitation can be achieved remotely through the web interface using low‑privilege credentials, and the attacker can target any user who subsequently accesses the vulnerable page. Given the absence of a low exploitation probability score, the risk is primarily driven by the moderate severity and the ease of exploitation via ordinary web traffic.
OpenCVE Enrichment