Executive brief
Adobe Experience Manager, a widely-used content management platform, contains a stored cross-site scripting vulnerability in form handling. An attacker with limited user privileges can inject malicious scripts into form fields that will execute in the browsers of other users who view the compromised content, potentially allowing credential theft, session hijacking, or unauthorized actions performed on behalf of victims.
Technical details
This is a stored cross-site scripting (XSS) vulnerability in Adobe Experience Manager versions 6.5.23 and earlier. The vulnerability exists in form field processing, where user input is not properly sanitized or escaped before being stored and re-rendered to other users. An attacker with low-privilege account access can inject arbitrary JavaScript into vulnerable form fields. The malicious payload persists in the system and executes client-side in the browsers of any user who accesses the affected page or form. A patch or update to a patched version is required to remediate this issue.
Affected products
- Adobe Experience Manager 6.5.23 and earlier
Timeline
- 2026-03-11: disclosed