Impact
A stored cross‑site scripting vulnerability allows a low‑privileged attacker to inject malicious JavaScript into vulnerable form fields. When a legitimate user visits the affected page, the attacker’s script executes in the victim’s browser, potentially leading to session hijacking, data theft, or manipulation of the user interface. The weakness is a classic input validation error (CWE‑79) and is classified as scope‑changed.
Affected Systems
Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are vulnerable. The flaw exists in the form handling components of these releases.
Risk and Exploitability
With a CVSS score of 5.4 the vulnerability is considered moderate. Exploitability is limited to users who can submit data to the vulnerable form fields; the attacker only needs low privileges to embed the payload. EPSS is not available and the issue is not listed in CISA’s KEV catalog, indicating no current active exploitation reports. The attack vector is likely through a web interface, and the attack is feasible in a typical multi‑tenant environment where users can submit content.
OpenCVE Enrichment