Executive brief
Adobe Experience Manager is a content management system used by enterprises to create, manage, and deliver digital content. A stored XSS vulnerability in form fields allows attackers to inject malicious scripts that execute in the browsers of users who view the affected pages. This could lead to account compromise, session hijacking, or theft of sensitive data displayed on those pages.
Technical details
The vulnerability is a stored cross-site scripting (XSS) flaw in Adobe Experience Manager versions 6.5.23 and earlier, affecting vulnerable form field components. An attacker can inject malicious JavaScript into form fields, which is then stored server-side and executed in the browsers of victims who access the page containing the vulnerable field. No special authentication or user interaction beyond viewing the page is required from the victim. The malicious script runs with the privileges of the victim's session, enabling credential theft, session hijacking, or further attacks. Adobe has issued patches; users should upgrade to patched versions.
Affected products
- Adobe Experience Manager 6.5.23 and earlier
Timeline
- 2026-03-11: disclosed