Impact
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross‑Site Scripting (XSS) vulnerability that can be abused by a low‑privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they view the affected page.
Affected Systems
The vulnerability impacts Adobe Experience Manager (AEM) 6.5.23 and all earlier releases. The affected product is identified by the CPE strings for Adobe Experience Manager, including the cloud service variant. No specific patch level is listed, but the issue is present in all releases up to 6.5.22.
Risk and Exploitability
The CVSS v3 score is 5.4 (Medium), and the EPSS score is less than 1%, indicating a low probability of exploitation at the time of analysis. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the attack vector is inferred to be local or web‑application‑based, requiring an attacker to submit form data that can be stored and later rendered as part of a page. The impact is limited to the victim’s browser session, potentially allowing theft of session cookies or malicious activity within the user’s context.
OpenCVE Enrichment