CVE-2025-64618: Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)
Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.
Affected Software
Event History
Frequently Asked Questions
Who is exposed to this issue?
Adobe Experience Manager users who browse a page containing a vulnerable form field with attacker-injected content may have malicious JavaScript execute in their browser. The issue requires an attacker with low-privileged access capable of submitting content to the vulnerable field.
Does exploitation require user interaction?
Yes. A victim must browse to the page that contains the vulnerable field and the stored malicious content.
What impact can successful exploitation have?
The vulnerability can allow malicious JavaScript to run in the victim's browser. The provided vector indicates low confidentiality and integrity impact, no availability impact, and a changed scope.