Impact
A stored Cross‑Site Scripting vulnerability exists in Adobe Experience Manager 6.5.24 and earlier, allowing a low‑privileged attacker to inject malicious scripts into form fields that are stored and later displayed to users. The injected JavaScript is executed in the context of the victim’s browser, which can lead to session hijacking, phishing, or the installation of malware. The weakness is a classic input‑validation flaw described by CWE‑79.
Affected Systems
Adobe Experience Manager servers running version 6.5.24, LTS SP1, 2026.04 or earlier are impacted. The flaw resides in the product’s form‑handling component and is present in all variants of the affected releases.
Risk and Exploitability
The CVSS score of 5.4 indicates a moderate severity. While an EPSS score is not available, the vulnerability does not appear in CISA’s KEV catalog. The attack requires a low‑privileged user to submit a malicious payload through a normal form and the content to be subsequently displayed to other users. Once the page containing the victim’s form is rendered, the embedded script runs in the victim’s browser context. The scope change means that the attacker can affect other users who view the same page.
OpenCVE Enrichment