Impact
Adobe Experience Manager is vulnerable to a stored Cross‑Site Scripting flaw that allows a low‑privileged attacker to inject and persist malicious JavaScript in form fields. When another user views the affected page, the script runs in that victim’s browser, enabling credential theft, phishing, or other client‑side attacks. The vulnerability changes scope, indicating that the impact is confined to the user interacting with the malicious page rather than affecting the server itself.
Affected Systems
Adobe Experience Manager versions 6.5, 6.5 LTS, and the Adobe Experience Manager As a Cloud Service are all affected by this flaw. Any deployment of these products that stores data from user input in form fields is potentially vulnerable.
Risk and Exploitability
The CVSS score of 5.4 classifies the vulnerability as moderate in severity. No EPSS data are available, and the issue is not listed in CISA’s Known Exploited Vulnerabilities catalog, suggesting limited field instruction. The attack requires an attacker to have access to edit a form field, but does not allow direct server‑side code execution. Exploitation is thus client‑side and requires a victim to load a page containing the malicious input.
OpenCVE Enrichment