Executive brief
Adobe Experience Manager, a widely-used content management and digital experience platform, contains a stored cross-site scripting vulnerability in form field handling. A low-privileged user could inject malicious scripts that execute when other users view affected pages, potentially stealing session tokens, redirecting users to phishing sites, or harvesting sensitive data entered into forms.
Technical details
This is a stored cross-site scripting (XSS) vulnerability in Adobe Experience Manager's form field handling. The vulnerability arises from insufficient input sanitization or output encoding when processing form data, allowing a low-privileged attacker to inject malicious JavaScript that persists in the application. The attack requires the attacker to have at least basic user privileges to submit or edit form fields. When a victim visits a page containing the poisoned field, the malicious script executes in their browser context, enabling session hijacking, credential theft, or redirection attacks. The scope is marked as changed, indicating the vulnerability may impact resources beyond the vulnerable component itself.
Affected products
- Adobe Experience Manager
Timeline
- 2026-09-08: disclosed