Executive brief
Adobe Experience Manager, a widely-used content management and digital experience platform, contains a stored cross-site scripting (XSS) vulnerability in form field handling. A low-privileged attacker can inject malicious scripts into form fields, which are then executed when other users view the affected content, potentially allowing theft of credentials, session hijacking, or malware distribution.
Technical details
This is a stored (persistent) XSS vulnerability in Adobe Experience Manager versions 6.5.23 and earlier, where malicious JavaScript injected into form fields is not properly sanitized before being displayed to other users. The vulnerability requires only low-privilege authentication to exploit, as the attacker can submit or modify form content. When a victim browses to a page containing the compromised form field, the injected script executes in their browser context with their privileges, enabling session hijacking, account takeover, or data exfiltration. Adobe has released patches for affected versions; users should upgrade to the latest patched release.
Affected products
- Adobe Experience Manager 6.5.23 and earlier
Timeline
- 2026-03-11: disclosed