Impact
A stored Cross‑Site Scripting vulnerability exists in Adobe Experience Manager that allows a low‑privileged attacker to insert malicious scripts into form fields. When a victim accesses a page that contains the compromised field, the injected JavaScript is executed in the victim’s browser context. The CVE description does not specify further exploitation beyond execution of the script.
Affected Systems
Adobe Experience Manager customers using version 6.5, 6.5 LTS, or the Cloud Service are affected. The flaw is present across these releases and involves any form fields that accept and store user input.
Risk and Exploitability
The CVSS score is 5.4, indicating a moderate severity. An EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is likely web‑based, with a low‑privileged attacker able to submit crafted input that the system stores without adequate sanitization. The scope is changed, meaning the impact can extend beyond the component that processes the input, allowing the injected code to run across the application for any user who views the affected page.
OpenCVE Enrichment