Impact
The vulnerability is a stored XSS flaw in Adobe Experience Manager 6.5.24 and earlier, allowing a low‑privileged attacker to embed malicious JavaScript into form fields. When a victim visits the compromised page, the script runs in the victim’s browser, potentially stealing credentials, hijacking sessions, or injecting phishing content. The weakness stems from insufficient sanitization of user input (CWE‑79).
Affected Systems
Adobe Experience Manager, versions 6.5.24 (LTS SP1), 2026.04 and all earlier releases.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate severity. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog, suggesting a lower likelihood of widespread exploitation at this time. Exploitation requires an attacker to submit malicious content through a writable form field; no elevated privileges are needed, but the attacker must have access to create or edit content. If successful, the attacker gains client‑side execution in the victim’s browser, with impact limited to confidentiality, integrity, or availability of the user session.
OpenCVE Enrichment