Impact
A stored Cross‑Site Scripting vulnerability allows a low‑privileged attacker to inject malicious JavaScript into form fields that are subsequently rendered and executed in a victim’s browser when they visit the affected page. The attack can potentially compromise confidential information, hijack user sessions, and deface content. The vulnerability’s scope change indicates that the XSS payload may execute with higher privileges than the attacker’s initial level, expanding the damage range.
Affected Systems
Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and any earlier releases are affected.
Risk and Exploitability
The CVSS score of 5.4 signifies a moderate risk level. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting that widespread exploitation is not currently documented. However, because the flaw is stored and can be triggered by a low‑privileged user, it poses a notable risk to all users of affected versions, especially in environments where users can submit form data. Exploitation requires the attacker to create or modify a form entry that contains malicious script, which is then stored and later served to any visitor.
OpenCVE Enrichment