CVE-2025-64588: Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)
Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.
Affected Software
Event History
Frequently Asked Questions
What access and user interaction are required to exploit this issue?
An attacker needs low-privileged access sufficient to submit content to a vulnerable form field. A victim must then browse to a page containing the injected field for the malicious JavaScript to execute.
Who is exposed to the impact?
Users who view pages containing attacker-controlled content in vulnerable form fields are exposed. Because the scope is changed, the script can affect a victim's browser session rather than being limited to the attacker's original security context.
Does this vulnerability affect an unauthenticated default deployment?
The provided information does not establish that unauthenticated attackers can exploit it or that all default configurations are affected. It specifically identifies a low-privileged attacker and vulnerable form fields as prerequisites.