Impact
Adobe Experience Manager is vulnerable to a stored Cross‑Site Scripting flaw that can be abused by a low‑privileged attacker to inject malicious JavaScript into vulnerable form fields. When a victim visits a page containing the stored input, the injected script is executed in the victim's browser, potentially enabling session hijacking, data theft, or defacement. Because the vulnerability modifies the scope of the application, its exploitation can affect multiple users who view the compromised content.
Affected Systems
Adobe Experience Manager 6.5, Adobe Experience Manager 6.5 LTS, and Adobe Experience Manager as a Cloud Service are all affected. No explicit version constraints are provided beyond the product families indicated.
Risk and Exploitability
The CVSS score of 5.4 indicates a moderate severity. With no EPSS information available and the vulnerability not listed in the CISA KEV catalog, the likelihood of exploitation appears moderate; however, the flaw allows compromised web content to run arbitrary JavaScript in the context of authenticated or guest users. The attack vector is inferred to be through the application’s form submission and rendering workflow, where user input is stored and later displayed without proper sanitization. By exploiting this, an attacker can obtain and execute code within the victim’s browser session.
OpenCVE Enrichment