Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)

CVE Details

Basic Information

Title Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)
Type cve
Published 2025-07-24T15:51:57.986Z
Modified 2025-07-24T15:51:57.986Z

Product Information

Vendor Adobe
Product Adobe Experience Manager
Version 0

CVSS Information

Base Score 5.4 (MEDIUM)
Attack Vector CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

AI Analysis

AI Description A stored XSS vulnerability in Adobe Experience Manager versions 6.5.22 and earlier allows low-privileged attackers to inject malicious scripts into form fields, which execute in victims’ browsers when viewing the affected page.
AI Severity Medium
AI Vendor Adobe
AI Product Adobe Experience Manager
AI Version 6.5.22 and earlier

Affected Products

  • Adobe Adobe Experience Manager 0

Additional Information

CWE List CWE-79
Source adobe

Description

Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

πŸ’­ Join the Security Discussion

πŸ”’ Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.