Impact
Adobe Experience Manager is vulnerable to a stored Cross‑Site Scripting flaw that enables a low‑privileged attacker to inject malicious scripts into form fields. When a user interacts with the affected page, the embedded JavaScript executes in the victim’s browser. The vulnerability is noted to change the scope of the compromise, indicating that the impact may extend beyond the immediate user environment.
Affected Systems
Affected systems include Adobe Experience Manager 6.5, Adobe Experience Manager 6.5 LTS, and Adobe Experience Manager as a Cloud Service. All installed instances of these packages are considered impacted until patched.
Risk and Exploitability
The CVSS score of 5.4 indicates a moderate severity level. No EPSS data is available, so the precise likelihood of exploitation cannot be quantified, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires a low‑privileged user who can submit data to the vulnerable form; successful injection leads to stored script execution in the browser of any user who views the page, with the potential for a broader impact due to the noted change in scope.
OpenCVE Enrichment