Impact
The vulnerability is a stored cross‑site scripting flaw in Adobe Experience Manager form fields. A low‑privileged attacker can inject malicious JavaScript that executes in the victim’s browser when the page containing the vulnerable field is accessed. Based on the description, it is inferred that the flaw involves a change in scope that allows the script to run with the victim’s privileges, potentially leading to data leakage, session hijacking, or further compromise.
Affected Systems
Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and all earlier releases are affected. All installations that include the vulnerable form fields are susceptible to exploitation.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate severity. EPSS data is unavailable but the flaw requires only a low‑privileged attacker to submit malicious input and a victim to visit the compromised page; the likelihood of exploitation is therefore non‑negligible. The vulnerability is not listed in CISA's KEV catalog, suggesting no known large‑scale exploitation yet. Attackers can gain the ability to execute arbitrary JavaScript in victims’ browsers, which can lead to credential theft or further system compromise.
OpenCVE Enrichment