Impact
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross‑Site Scripting (XSS) vulnerability that could be abused by a low‑privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Affected Systems
Affected systems are Adobe Experience Manager 6.5.23 and all earlier releases, including the 6.5 LTS and SP1 builds. The common platform enumeration list confirms that all 6.5 variants are susceptible.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate severity, while the EPSS score of less than 1% suggests a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires a low‑privileged attacker who can submit data through a form field within the application; no remote code execution or purely network‑based exploit is described.
OpenCVE Enrichment