Impact
The vulnerability is a stored cross‑site scripting flaw in Adobe Experience Manager versions 6.5.23 and earlier that permits a low‑privileged attacker to inject malicious JavaScript into vulnerable form fields. The injected script executes in a victim’s browser when the page containing the field is viewed, potentially compromising the confidentiality, integrity, or availability of the victim’s session. The weakness is classified as CWE‑79. Based on the description, it is inferred that the attack vector is through standard form inputs submitted by attackers.
Affected Systems
Adobe Experience Manager versions 6.5.23 and earlier, including the AEM Cloud Service and on‑premise releases identified by the provided CPE strings, are affected. All installations that permit user input via form fields are potentially vulnerable.
Risk and Exploitability
The CVSS score is 5.4, indicating moderate severity, while the EPSS score is below 1%, suggesting a low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Attackers can exploit the flaw remotely through form inputs without administrative privileges, making it broadly accessible to many threat actors.
OpenCVE Enrichment