Impact
The vulnerability is a stored Cross‑Site Scripting flaw in Adobe Experience Manager Forms JEE. An attacker with high privileges can inject malicious JavaScript into form fields that persist in the system. When a victim visits a page containing the compromised field, the script runs within their browser, enabling credential theft, session hijacking, or arbitrary client‑side code execution. The issue is a stored XSS, meaning the payload remains in the application and can affect many users, and the impact is further amplified because the scope of affected components has been widened.
Affected Systems
Adobe Experience Manager Forms JEE is the product affected, specifically the LTS SP1 release, version 6.5.24.0 and earlier. No other vendors or products are listed in the data.
Risk and Exploitability
The CVSS score of 5.9 indicates moderate severity. The EPSS metric is not available, so the likelihood of exploitation is uncertain. The vulnerability is not listed in the CISA KEV catalog, suggesting no known widespread exploitation. Based on the description, it is inferred that the attacker would need elevated privileges to inject the malicious script, limiting the opportunity for unauthenticated remote exploitation. Once injected, however, any user who views the form will be exposed to script execution.
OpenCVE Enrichment