Executive brief
Adobe Experience Manager, a platform used by organizations to create and manage digital content and web experiences, contains a stored Cross-Site Scripting vulnerability in form fields. An attacker with low-level access could inject malicious scripts that execute in the browsers of other users viewing the affected form, potentially allowing credential theft, session hijacking, or other attacks against those users.
Technical details
The vulnerability is a stored Cross-Site Scripting (XSS) flaw in form field handling in Adobe Experience Manager versions 6.5.23 and earlier. The root cause is insufficient input validation or output encoding of user-supplied data in form fields, allowing an attacker with low-level privileges to inject malicious JavaScript. The injected script persists on the server and executes in the browsers of users who view the affected page, enabling session hijacking, credential theft, or malware distribution. No network traversal or special conditions are required beyond low-level access to the system; remediation requires patching to a version later than 6.5.23.
Affected products
- Adobe Experience Manager 6.5.23 and earlier
Timeline
- 2026-03-11: disclosed