Impact
Adobe Experience Manager is affected by a stored cross‑site scripting flaw that can be abused by an attacker with limited privileges to inject JavaScript code into vulnerable form fields. When a victim visits the page containing the stored payload, the script executes in the context of the victim’s browser, potentially leading to session theft, defacement, or other client‑side attacks. The vulnerability changes scope, implying that the impact may extend beyond the original container and affect other authenticated users or applications.
Affected Systems
The flaw affects Adobe Experience Manager 6.5, including the 6.5 Long Term Support release and the Cloud Service deployment. No specific patch versions were listed, so all installations of these products remain vulnerable until updated.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate risk. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog, so its exploitation probability is not known to be high. The likely attack vector is via form input that accepts user supplied data; a low‑privileged user who can submit content to the affected forms can embed malicious scripts. Once the payload is stored and retrieved by a legitimate user, the attacker’s script runs without further actions required beyond form submission.
OpenCVE Enrichment