CVE-2025-64610: Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)
Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.
Affected Software
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
An attacker needs low-privileged access sufficient to submit content to vulnerable form fields. Exploitation also requires a victim to browse to a page containing the injected script.
What is the likely impact on affected users?
Malicious JavaScript can execute in the victim's browser. The changed scope and low confidentiality and integrity impacts indicate the issue can affect a different security authority than the attacker.
Are deployments affected by default?
The available information does not state whether vulnerable form fields are enabled or exposed in a default Adobe Experience Manager configuration.