CVE-2025-46837: Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)
Adobe Experience Manager versions 6.5.22 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. A successful attacker can abuse this to achieve session takeover, increasing the confidentiality and integrity impact as high.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-46837?
CVE-2025-46837 is classified as a high severity vulnerability due to the potential for reflected XSS attacks.
How do I fix CVE-2025-46837?
To mitigate CVE-2025-46837, upgrade Adobe Experience Manager to version 6.5.23.0 or later.
Who is affected by CVE-2025-46837?
CVE-2025-46837 affects Adobe Experience Manager versions up to 6.5.22 and earlier, including AEM Cloud Service versions up to 2025.5.0.
What kind of attacks can CVE-2025-46837 enable?
CVE-2025-46837 can allow low privileged attackers to inject malicious scripts into vulnerable form fields, leading to XSS attacks.
Can user data be compromised by CVE-2025-46837?
Yes, CVE-2025-46837 can potentially compromise user data through execution of malicious JavaScript in the victim's browser.