Impact
Adobe Experience Manager versions 6.5.23 and earlier are vulnerable to a stored Cross‑Site Scripting flaw. An attacker can embed malicious JavaScript into form fields that are subsequently displayed in web pages viewed by users. The script executes in the victim’s browser when the affected page is loaded, exposing the user to untrusted code. This weakness is identified as CWE‑79.
Affected Systems
The vulnerability affects Adobe Experience Manager 6.5, all service packs up to and including 6.5.23, when deployed on‑premises or through the AEM Cloud Service. CPE entries for the on‑premises configuration (6.5 lts, 6.5 sp1 lts) and the cloud service configuration are included. No specific patch version is listed in the supplied data.
Risk and Exploitability
CVSS score of 5.4 indicates moderate severity. EPSS score is below 1%, implying a low likelihood of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is web‑based and is inferred from the fact that an attacker must supply malicious input through a vulnerable form; this inference is not directly stated in the data.
OpenCVE Enrichment