Executive brief
Adobe Experience Manager, a web content management platform used by enterprises to build and manage websites, contains a stored cross-site scripting vulnerability in form fields. An attacker can inject malicious scripts that execute when users view affected pages, potentially allowing account takeover, credential theft, or defacement of content.
Technical details
The vulnerability is a stored Cross-Site Scripting (XSS) flaw in form field handling within Adobe Experience Manager. An attacker can inject malicious JavaScript into vulnerable form fields, which persists in the application and executes in the browsers of users who subsequently view the compromised page. This requires the attacker to have the ability to submit or modify form data, but no authentication or elevated privileges appear to be strictly required based on the advisory description. The impact allows arbitrary script execution in the context of the victim's session, potentially leading to session hijacking or data theft.
Affected products
- Adobe Experience Manager 6.5.23 and earlier
Timeline
- 2026-03-11: disclosed