Impact
A stored cross‑site scripting vulnerability exists in Adobe Experience Manager that allows a low‑privileged attacker to inject malicious JavaScript into vulnerable form fields. When a victim visits the page containing the injected script, the code executes in the victim’s browser, potentially stealing cookies, hijacking sessions, or redirecting the user to malicious sites. Scope changes indicate the attack could affect the entire web application rather than just a single form.
Affected Systems
Adobe Experience Manager 6.5, the 6.5 LTS release, and the Experience Manager as a Cloud Service are impacted. Any instance running these versions without the vendor‑supplied fix is vulnerable.
Risk and Exploitability
The CVSS score of 5.4 classifies this issue as moderate severity, and the EPSS score is not available, so the likelihood of exploitation is uncertain but cannot be ruled out. The vulnerability is not listed in CISA’s KEV catalog, suggesting no known widespread exploitation. However, given that a low‑privileged attacker can submit data that is stored and later rendered, an attacker could leverage the XSS to compromise end users within the same organization or its customers, posing a risk especially in environments where form data is publicly visible.
OpenCVE Enrichment