CVE-2025-64584: Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)
Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.
Affected Software
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
An attacker needs low-privileged access and must be able to submit malicious script content through a vulnerable form field. Exploitation also depends on a victim browsing to the page that displays the stored content.
What is the likely impact on users who view an affected page?
Malicious JavaScript can execute in the victim's browser when they browse to a page containing the vulnerable field. The reported impact includes limited confidentiality and integrity effects, and the vulnerability has changed scope.