Impact
This CVE describes a stored cross‑site scripting vulnerability in Adobe Experience Manager that could be abused by a low‑privileged attacker to inject malicious scripts into vulnerable form fields. When a victim navigates to the page containing the stored input, the malicious JavaScript executes in the victim’s browser, enabling possible session hijacking, credential theft, or defacement. Scope is changed as the vulnerability allows the attacker to affect other users who view the compromised content.
Affected Systems
The vulnerability affects Adobe Experience Manager 6.5, Adobe Experience Manager 6.5 LTS, and Adobe Experience Manager as a Cloud Service. These versions should be reviewed for the presence of the issue.
Risk and Exploitability
The CVSS score of 5.4 indicates a medium‑severity risk. EPSS is not available, and the vulnerability is not listed in CISA’s KEV catalog, implying no known widespread exploitation at the time of assessment. The attack vector is likely remote, via the software’s form capabilities; a low‑privileged contributor can exploit the flaw, and any user who views the populated page may be impacted. Given the stored nature of the payload, the risk is amplified by the persistence of the malicious script across sessions and users.
OpenCVE Enrichment