Impact
The vulnerability is a stored cross‑site scripting flaw in Adobe Experience Manager that allows a low‑privileged attacker to inject malicious JavaScript into vulnerable form fields. When a user visits a page that contains the stored data, the injected script executes in that user’s browser.
Affected Systems
Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and all earlier releases are affected. These versions are used by organizations that provide web content through Adobe Experience Manager’s form‑handling capabilities.
Risk and Exploitability
The CVSS score of 5.4 indicates a moderate risk. The EPSS score is not available, so the current exploitation probability is unknown. The issue is not listed in CISA’s KEV catalog. The flaw only requires an attacker to have low‑privilege access to submit a form; once the payload is stored, any user who views the affected page will have the malicious script executed in their browser.
OpenCVE Enrichment