Impact
Adobe Experience Manager Forms JEE is vulnerable to a stored Cross‑Site Scripting flaw that enables a high‑privileged attacker to inject malicious JavaScript into form fields. The injected code is persisted and executed whenever a victim loads the affected page, potentially giving the attacker elevated access or control over the victim's account or session. The weakness is a classic input validation failure consistent with CWE‑79.
Affected Systems
The vulnerability affects Adobe Experience Manager 6.5 Forms JEE and its LTS variant, specifically the Forms JEE component. No specific affected version numbers are listed, so all releases of these products should be considered at risk until patched.
Risk and Exploitability
With a CVSS score of 8.1 this vulnerability represents high severity. The EPSS score is not available, and the issue is not listed in CISA’s KEV catalog, indicating it has not yet been widely exploited. The likely attack vector requires a high‑privileged or privileged user to submit malicious content, which then becomes stored and later executed in an end‑user’s browser. Once the payload is delivered via the stored XSS, it can compromise confidentiality, integrity, and availability of the affected system from the perspective of the victim’s session.
OpenCVE Enrichment