Impact
A stored cross‑site scripting (CWE‑79) vulnerability allows an attacker who can submit data to vulnerable form fields to embed malicious JavaScript. When a victim later views a page containing the stored data, the browser executes the attacker’s code. The ability to execute arbitrary script can lead to theft of authentication tokens, session hijacking, or malicious manipulation of web content. The CVE notes a scope change, indicating that user‑controlled input may affect higher privilege operations within the system.
Affected Systems
The affected products are Adobe Experience Manager 6.5, Adobe Experience Manager 6.5 LTS, and Adobe Experience Manager as a Cloud Service. No specific minor or patch versions are indicated in the advisory, so any deployed instance of these product lines is potentially vulnerable.
Risk and Exploitability
The CVSS score of 5.4 indicates a moderate severity. The EPSS score is unavailable, and the vulnerability is not listed in the CISA KEV catalog, suggesting that widespread exploitation is not yet observed. Based on the description, the likely attack vector is local: an attacker with limited privileges who can submit data to the system’s form fields. Successful exploitation requires the attacker to place malicious payloads in fields that are later rendered to other users, after which the payload is executed in those users’ browsers.
OpenCVE Enrichment