Impact
Adobe Experience Manager is affected by a stored XSS vulnerability that allows a low‑privileged attacker to inject malicious scripts into susceptible form fields. The injected JavaScript is executed in the victim's browser when the page containing the field is loaded, potentially enabling credential theft, session hijacking, or defacement. Scope is changed, indicating that a successful exploitation could elevate the attacker’s privileges within the application.
Affected Systems
Affected vendors and products include Adobe Experience Manager 6.5, the 6.5 LTS release, and the Adobe Experience Manager as a Cloud Service offering. Any instance of these products that has not applied the latest security update is vulnerable. No specific patch versions are listed in the data, but the reference to Adobe's security bulletin implies that an update exists.
Risk and Exploitability
With a CVSS score of 5.4, the vulnerability is considered moderate; the EPSS score is currently unavailable, and it is not listed in the CISA Known Exploited Vulnerabilities catalog. Because the attack requires only a low‑privileged user to supply input in a vulnerable form, the feasibility of exploitation is high for users with legitimate access to those forms. However, the potential impact is limited to the victim’s browser, not the underlying server, and does not enable remote code execution on the host.
OpenCVE Enrichment