Impact
Adobe Experience Manager 6.5.23 and earlier allow a low‑privileged attacker to inject malicious JavaScript into form fields. The injected script is stored and later executed whenever a victim views the page containing the field. This can lead to session hijacking, credential theft, or defacement of the site, compromising the confidentiality and integrity of user data.
Affected Systems
The vulnerability affects Adobe Experience Manager versions 6.5.23 and earlier. The affected products include the standard AEM installation as well as the AEM Cloud Service and the LTS 6.5 releases (6.5, 6.5sp1).
Risk and Exploitability
The CVSS base score of 5.4 indicates moderate severity. The EPSS score is below 1%, and the vulnerability is not listed in CISA’s KEV catalog, suggesting limited current exploitation activity. Exploitation requires an attacker to supply malicious input via a form field and for a victim to later view the resulting page; the attack vector is likely local to the application, but can have broader impact through phishing of legitimate users.
OpenCVE Enrichment