Executive brief
Adobe Experience Manager, a widely-used content management system for enterprises, contains a stored cross-site scripting vulnerability in form field handling. An attacker with low-level user privileges can inject malicious JavaScript code that persists in the system and executes when legitimate users view the affected page, potentially allowing account takeover, credential theft, or malware distribution.
Technical details
The vulnerability is a stored (persistent) cross-site scripting flaw in Adobe Experience Manager versions 6.5.23 and earlier, where user-supplied input in certain form fields is not properly sanitized before storage and rendering. A low-privileged authenticated attacker can inject malicious JavaScript that executes in the context of any user who views the affected page, bypassing same-origin policy protections through the trusted domain. The attack requires the attacker to have user-level access to the AEM instance and the victim to browse to a page containing the injected payload. No patch details are provided in the advisory text.
Affected products
- Adobe Experience Manager 6.5.23 and earlier
Timeline
- 2026-03-11: disclosed