Impact
Adobe Experience Manager is affected by a stored Cross‑Site Scripting vulnerability that allows a low‑privileged attacker to inject malicious scripts into certain form fields. When a user views a page containing the compromised field, the injected JavaScript runs in the browser with the victim’s privileges, enabling actions such as defacement, session hijacking, or data exfiltration. The vulnerability is classified as CWE‑79 and is a stored XSS with a scope modification.
Affected Systems
The affected software includes Adobe Experience Manager 6.5, Adobe Experience Manager 6.5 LTS, and the Adobe Experience Manager cloud service offering. No specific version sub‑range is mentioned; therefore all releases within these product lines are potentially impacted.
Risk and Exploitability
The CVSS score is 5.4, indicating a medium severity. The EPSS score is less than 1 %, suggesting that real‑world exploitation is unlikely but still possible. The vulnerability is not listed in the CISA KEV catalog. A low‑privileged authenticated user can submit payloads through vulnerable form fields; the attacker does not need elevated permissions or unauthenticated access. Once inserted, the data is stored and served unfiltered to any viewer, meaning the impact can reach a broad cohort if the page is widely accessed. Because the attack surface requires user interaction, the exploitation probability remains low, but the potential damage to user trust and data confidentiality could be significant.
OpenCVE Enrichment