Impact
Adobe Experience Manager is vulnerable to a stored cross‑site scripting flaw that allows an attacker with limited privileges to inject malicious JavaScript into form fields. When a victim views a page containing the compromised field, the injected script executes in the victim’s browser, potentially enabling the attacker to steal session data, deface content, or perform actions on behalf of the user. The description notes that the vulnerability’s scope is changed, indicating the ability to affect code outside the initially targeted component. The weakness is identified as CWE‑79.
Affected Systems
Affected products are Adobe Experience Manager 6.5, its long‑term support branch, and the cloud‑service deployment of the platform. The vulnerability applies to all installations that allow user‑supplied content to be rendered within form fields without proper sanitization.
Risk and Exploitability
The CVSS score of 5.4 classifies the flaw as medium severity. No EPSS metric is available, so the exploitation probability cannot be quantified from the data. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is an attacker injecting scripts into insecure form fields that are later rendered to other users’ browsers. No additional prerequisites or complex conditions are stated, so typical authenticated or unprivileged users with write access to form content can abuse this flaw. The impact is confined to the victim’s browser execution context and does not grant direct access to the underlying system or data storage.
OpenCVE Enrichment