Impact
Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier can be affected by a stored Cross‑Site Scripting vulnerability that allows a low‑privileged attacker to inject malicious JavaScript into vulnerable form fields. When a victim visits the page containing the injected payload, the script is executed in their browser, potentially compromising confidentiality and integrity of the victim session. The scope of the flaw has been changed, indicating that it may affect higher privileges than originally reported.
Affected Systems
The affected product is Adobe Experience Manager by Adobe, specifically versions 6.5.24 and earlier, including the LTS SP1 release and the 2026.04 release.
Risk and Exploitability
The CVSS score is 5.4, placing the vulnerability in the medium severity range. EPSS data is not available and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector involves an attacker with the ability to submit data through a vulnerable form field; exploitation would require access to the affected form. No explicit exploitation conditions are documented, but the flaw is exploitable in a typical web‑application scenario where form data is stored and later rendered to users without adequate sanitization.
OpenCVE Enrichment