Impact
Adobe Experience Manager is affected by a stored Cross‑Site Scripting vulnerability. A low‑privileged attacker can inject malicious JavaScript into vulnerable form fields. When a victim opens the page containing the stored payload, the script runs in their browser. The flaw is a classic input validation issue (CWE‑79) that changes the scope of the affected content and data.
Affected Systems
The vulnerability applies to Adobe Experience Manager 6.5 and its LTS version, as well as the Cloud Service edition. No specific build numbers are provided, so every deployment of these products is potentially impacted until a patch is installed.
Risk and Exploitability
The vulnerability scores a CVSS of 5.4, indicating moderate severity. The EPSS score is not available and the flaw has not been reported in the KEV list. Attacks would require the attacker to be able to submit data to a vulnerable form; the stored payload is then displayed to any user who visits the affected page, which can lead to session hijacking or credential theft. The likelihood of exploitation in the wild is uncertain, but the impact on confidentiality, integrity, and availability is limited to the victim’s browser environment.
OpenCVE Enrichment