Impact
Adobe Experience Manager is affected by a stored Cross‑Site Scripting vulnerability that allows a low‑privileged attacker to inject malicious scripts into form fields. If executed, the injected JavaScript runs in the victim’s browser when they view the page containing the vulnerable field, potentially leading to data theft, session hijacking, or defacement. The vulnerability is a classic Content Injection flaw classified as CWE‑79.
Affected Systems
Adobe Experience Manager 6.5, Adobe Experience Manager 6.5 LTS, and Adobe Experience Manager as a Cloud Service are impacted. Any deployment of these versions that accepts user‑supplied input in form fields is vulnerable.
Risk and Exploitability
The CVSS score is 5.4, indicating a moderate impact. No EPSS score is available and the vulnerability is not listed in the CISA KEV catalog, suggesting limited evidence of exploitation in the wild. The likely attack vector is through the web application’s form field submission mechanism, inferred from the description of injected scripts in form fields. Successful exploitation requires a low‑privilege attacker to submit crafted content that the system then stores and displays without proper sanitization.
OpenCVE Enrichment