Executive brief
Adobe Experience Manager, a content management and digital asset platform used by enterprises to build and manage web properties, contains a stored cross-site scripting (XSS) vulnerability in form fields. A low-privileged attacker can inject malicious JavaScript that executes when legitimate users view the affected page, potentially compromising user sessions, stealing credentials, or redirecting victims to phishing sites.
Technical details
A stored XSS vulnerability exists in Adobe Experience Manager 6.5.23 and earlier in form field handling. The vulnerability allows a low-privileged attacker to inject malicious scripts into vulnerable form fields; these scripts are then executed in the browsers of users who view the containing page. The attack requires an authenticated attacker with low privileges to inject the payload, and the vulnerability persists in the application database (stored XSS). Successful exploitation enables session hijacking, credential theft, or malware distribution to legitimate users. Patches are available from Adobe; see APSB26-24.
Affected products
- Adobe Experience Manager 6.5.23 and earlier
Timeline
- 2026-03-11: disclosed