Executive brief
Adobe Experience Manager, a widely-used enterprise content management platform, contains a stored cross-site scripting vulnerability in form handling. An attacker with low-level access can inject malicious scripts into form fields, which execute in the browsers of other users who view the affected pages, potentially stealing credentials, sessions, or sensitive data.
Technical details
This is a stored XSS vulnerability (CWE-79) in Adobe Experience Manager versions 6.5.23 and earlier, affecting form field processing. The vulnerability allows a low-privileged attacker to inject malicious JavaScript into vulnerable form fields; the injected scripts persist in the application's data store and execute in the context of other users' browsers when they access pages containing the vulnerable field. Attack preconditions include low-privilege account access to the application. An attacker can execute arbitrary JavaScript in victims' sessions, potentially leading to account compromise, data theft, or malware delivery. Patch availability and specific fix details are not confirmed in the provided advisory text.
Affected products
- Adobe Experience Manager 6.5.23 and earlier
Timeline
- 2026-03-11: disclosed