Impact
Adobe Experience Manager is affected by a stored Cross‑Site Scripting vulnerability that could be abused by a low‑privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed when a victim visits the page containing the field. The vulnerability changes the security scope, allowing an attacker to persistently impact the user session or content integrity.
Affected Systems
Affected products include Adobe Experience Manager 6.5, 6.5 LTS, and Adobe Experience Manager as a Cloud Service. No specific version constraints are listed, so all current releases of these offerings are potentially susceptible.
Risk and Exploitability
The CVSS score of 5.4 denotes a moderate impact; the EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. An attacker with low privileges could exploit the flaw through editable content or form fields, potentially injecting script that runs in the victim’s browser. Because the attacker only needs content editing rights, the risk of exploitation is considered moderate but should be mitigated promptly.
OpenCVE Enrichment