Impact
The vulnerability allows a low-privileged attacker to inject malicious scripts into certain form fields that are stored and rendered later in a victim’s browser. When a target loads a page containing the compromised field, the embedded JavaScript executes with the victim’s browser privileges, potentially enabling data theft or session hijacking. The flaw is a classic input-validation failure categorized as CWE-79.
Affected Systems
Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected. The issue applies to the default form components shipped with these releases.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate severity. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog. The attack requires the attacker to submit malicious content to a form that is subsequently displayed to victims, implying a local exploitation path. Given the change in scope, an attacker can influence the wider user base but does not gain full system compromise.
OpenCVE Enrichment