Impact
Adobe Experience Manager is affected by a stored Cross‑Site Scripting vulnerability. A low‑privileged attacker can insert malicious script into vulnerable form fields, which is then executed in a victim’s browser when the page containing the field is viewed. The vulnerability’s scope is changed, indicating that the attacker may acquire higher privileges than the individual who crafted the input.
Affected Systems
The affected products are Adobe Experience Manager versions 6.5, 6.5 LTS, and the Experience Manager as a Cloud Service offering.
Risk and Exploitability
The CVSS score is 5.4, reflecting moderate severity. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, suggesting a lower likelihood of widespread exploitation. The likely attack vector is through web‑based form submissions that are stored and later rendered to other users. Successful exploitation requires the attacker to be able to submit content that is stored and displayed without proper input sanitization.
OpenCVE Enrichment