Impact
Adobe Experience Manager versions 6.5.23 and earlier are vulnerable to a stored Cross‑Site Scripting (XSS) flaw (CWE‑79). An attacker can inject malicious JavaScript into data that is stored in form fields; when a victim’s browser loads the affected page, the script executes, potentially enabling the attacker to hijack the user session or exfiltrate sensitive information.
Affected Systems
The affected product is Adobe Experience Manager from Adobe. All 6.5 releases—including the base 6.5, the LTS and SP1 variants, as well as the Cloud Service—are impacted. Any system running a version of the platform that is 6.5.23 or earlier is therefore at risk.
Risk and Exploitability
The CVSS base score of 5.4 indicates moderate severity. The EPSS score of less than 1% suggests a low likelihood of current exploitation, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires submission of malicious data to a vulnerable form field; the official description does not state whether authentication is required, so it is unclear if the attacker must be authenticated or can act as an unauthenticated user.
OpenCVE Enrichment