Impact
A stored Cross‑Site Scripting vulnerability allows a low‑privileged attacker to inject malicious JavaScript into form fields of Adobe Experience Manager. When a user opens a page containing the compromised field, the browser executes the injected script in the victim’s context. This may lead to credential theft, session hijacking, or other malicious actions within the user’s session. The vulnerability changes the scope to include the attacker’s impact on end users.
Affected Systems
Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected. The attack applies across the product line of this Adobe component; this inference is based on the version list provided.
Risk and Exploitability
The CVSS score of 5.4 indicates a moderate severity. EPSS data is not available, and the vulnerability is not listed in CISA’s KEV catalog, suggesting that it is not widely exploited at present. The likely attack vector is a low‑privileged attacker submitting a crafted request that stores malicious script in a form field; the script is then executed when any user browses the related page. Exploitation does not require elevated privileges but relies on user interaction to load the vulnerable page.
OpenCVE Enrichment