Impact
Adobe Experience Manager contains a stored Cross‑Site Scripting vulnerability that allows a low‑privileged attacker to inject malicious JavaScript into form fields. When a victim visits a page that contains the injected script, the code runs in the victim’s browser. The CVE states that the scope of the vulnerability is changed, indicating potential impact beyond the initially affected component, but no further exploitation outcomes are detailed in the advisory.
Affected Systems
The affected products are Adobe Experience Manager 6.5, the LTS variant of 6.5, and the cloud‑based Adobe Experience Manager service. All deployments of these products that have not applied Adobe’s latest patch are vulnerable. No specific revision numbers are provided beyond the major product line, so any instance of these products is considered at risk until an update is confirmed.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate severity, and the EPSS score of less than 1 % suggests a very low likelihood of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is inferred to involve submission of malicious content through a vulnerable form field, requiring the attacker to have the ability to submit data, after which the malicious JavaScript is stored and subsequently executed when a victim views the affected page. Because the flaw is scope‑changing, a successful exploitation could theoretically extend beyond the initially impacted component, yet the low EPSS and lack of known exploits imply the immediate risk remains moderate.
OpenCVE Enrichment