Impact
Adobe Experience Manager versions 6.5.23 and earlier contain a stored cross‑site scripting vulnerability that allows a low‑privileged attacker to inject malicious JavaScript into vulnerable form fields; when a victim visits the affected page the script executes in the victim’s browser. This can lead to the theft or manipulation of user data, credential hijacking, or other malicious actions performed under the victim’s identity.
Affected Systems
The vulnerability affects Adobe Experience Manager, specifically releases 6.5.23 and earlier. The associated CPE identifiers indicate the packaging for the 6.5 LTS releases and the cloud service variant. No newer versions are listed as affected.
Risk and Exploitability
The CVSS base score of 5.4 indicates moderate severity, and the EPSS score of less than 1% suggests a low probability of widespread exploitation at this time. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires only that an attacker be able to submit data to a vulnerable form field, which can be achieved with very low privileges; the victim must then visit the page containing the stored script for the payload to execute.
OpenCVE Enrichment