CVE-2025-64830: Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)
Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.
Affected Software
Event History
Frequently Asked Questions
What access and interaction are required for exploitation?
An attacker needs low-privileged access to inject malicious script into vulnerable form fields. A victim must then browse to a page containing the affected field for the JavaScript to execute in the victim's browser.
Which users are exposed to the malicious script?
Users who browse pages containing a vulnerable form field with attacker-injected content are exposed. The issue has changed scope, so the impact can extend beyond the attacker’s own security context.