Impact
The vulnerability is a stored Cross‑Site Scripting flaw (CWE‑79) that allows a low‑privileged attacker to embed malicious JavaScript into form fields that are then rendered when other users view the page. Once the script is executed in a victim’s browser it can hijack the user session, steal credentials, or perform other malicious actions. Because the attack payload is stored, it can affect anyone who visits the compromised form, making the exploitation effective even after the attacker’s session ends.
Affected Systems
Adobe Experience Manager is the affected product. Versions 6.5.24, the LTS SP1 build, and the 2026.04 release and earlier are vulnerable. No later versions are listed as affected in the CVE entry.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate overall severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The attack requires only low privilege and relies on the web form input path; a legitimate user or an attacker with access to submit content can inject the payload, and any subsequent viewer of the page will be exposed to the script.
OpenCVE Enrichment