Impact
Adobe Experience Manager contains a stored XSS flaw that lets a low‑privileged attacker inject malicious JavaScript into certain form fields. When a victim later views the affected page, the script runs in their browser, potentially compromising session data or defacing content. The vulnerability is a classic input validation weakness resulting in client‑side code execution.
Affected Systems
Adobe Experience Manager 6.5, Adobe Experience Manager 6.5 LTS, and the Cloud Service version are all affected. No further version granularity was provided in the vendor data.
Risk and Exploitability
The CVSS score of 5.4 indicates a moderate risk, and there is no EPSS data or KEV listing, suggesting no widespread exploitation has been observed. Attackers can exploit the flaw by submitting malicious payloads through the vulnerable form, and the low privilege required mitigates the overall impact compared with higher‑privilege attacks. Nonetheless, since JavaScript executes in the victims’ browsers, the risk to confidentiality and integrity of user data remains significant.
OpenCVE Enrichment