Impact
Adobe Experience Manager can store malicious JavaScript in user‑controlled form fields. An attacker with low privileges can submit a payload that is later rendered in a victim’s browser when the destination page is viewed. The vulnerability allows arbitrary script execution in the context of the current user, potentially enabling client‑side data theft, session hijack, or other malicious actions depending on the victim’s privileges. The flaw exploits improper input handling and output encoding, leading to a traditional stored cross‑site scripting condition.
Affected Systems
The flaw affects Adobe Experience Manager 6.5, 6.5 LTS and the as‑a‑service edition available in Adobe’s cloud portfolio. No specific minor or patch versions are listed in the advisory, so any installation of the mentioned product lines is considered vulnerable until the vendor’s fix is applied.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate severity. Because the EPSS score is not available and the vulnerability is not listed in CISA’s KEV catalog, the likelihood of public exploitation is uncertain but not negligible. The attack vector is inferred to be remote via the web interface; an attacker only needs to submit a malicious form entry to create a stored payload. The scope is changed, meaning that an attacker could affect the entire system by compromising the application’s output handling.
OpenCVE Enrichment