Impact
The vulnerability allows a low‑privileged attacker to inject malicious JavaScript into stored form fields within Adobe Experience Manager. When a victim views the affected page, the script executes in the victim’s browser, providing the attacker with opportunities for further exploitation. This stored XSS flaw changes scope, meaning the impact extends to any authenticated user who can view the compromised content.
Affected Systems
Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04, and all earlier releases are affected. No other vendors or products are listed.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate severity. The EPSS score is unavailable, so the exploitation probability is unclear, and the vulnerability is not listed in CISA KEV. With no mention of remote network exploitation in the description, the likely attack vector involves a web‑based form submission; an attacker needs only low privileges to inject the payload. The scope change suggests that an attacker can affect all users who view the stored content.
OpenCVE Enrichment