Impact
Adobe Experience Manager versions 6.5.23 and earlier have a stored Cross‑Site Scripting vulnerability that allows a low‑privileged attacker to inject malicious JavaScript into vulnerable form fields. When a victim later visits a page containing the injected code, the script runs in the victim’s browser, potentially compromising session data or defacing content. This weakness is a classic input‑validation error (CWE‑79).
Affected Systems
Affected product: Adobe Experience Manager. All releases up to and including version 6.5.23, including the standard 6.5 and the SP1 LTS variant, are impacted. The vulnerability exists in the base platform as well as in the Adobe Experience Manager cloud service configuration, as indicated by the provided CPE identifiers.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate severity. An EPSS score of less than 1% suggests a low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires a low‑privileged attacker to submit data through a vulnerable form field; therefore, the attack vector is inferred to be internal or via compromised user credentials.
OpenCVE Enrichment