Impact
Adobe Experience Manager is affected by a stored Cross‑Site Scripting vulnerability (CWE‑79) that can be abused by low‑privileged attackers to inject malicious scripts into vulnerable form fields. The malicious JavaScript may be executed in a victim's browser when they view a page containing the payload. The flaw is scope‑changing, meaning that exploitation may affect more than the initially targeted resource.
Affected Systems
Affected releases include Adobe Experience Manager 6.5, the Adobe Experience Manager 6.5 Long‑Term Support edition, and Adobe Experience Manager as a Cloud Service. All builds of these releases are potentially impacted; no specific sub‑version ranges are provided.
Risk and Exploitability
The CVSS base score of 5.4 indicates medium severity, while the EPSS score of less than 1% indicates a low probability of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. An attacker with low privileges can submit a malicious payload into a form that is subsequently stored and rendered to other users, with the scope change implying possible impact beyond a single individual or resource.
OpenCVE Enrichment