Executive brief
Adobe Experience Manager is a widely-used content management and digital experience platform used by enterprises to manage websites and digital content. A stored cross-site scripting vulnerability allows attackers with low-level access to inject malicious scripts into form fields. When legitimate users view pages containing these poisoned fields, the malicious code executes in their browser, potentially leading to session hijacking, credential theft, or unauthorized actions performed on their behalf.
Technical details
This is a stored cross-site scripting (XSS) vulnerability in Adobe Experience Manager's form field handling. The vulnerability allows low-privileged attackers to inject malicious JavaScript into vulnerable form fields; the injected script persists in the application's database and executes whenever a user views the affected page. The attack requires the attacker to have form submission capabilities but does not require authentication or user interaction beyond normal page browsing. An attacker can achieve session hijacking, credential theft, administrative account takeover, or defacement. Patches are available for versions later than 6.5.23.
Affected products
- Adobe Experience Manager 6.5.23 and earlier
Timeline
- 2026-03-11: disclosed