CVE-2025-64838: Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)
Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.
Affected Software
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
The attacker needs low-privileged access and must be able to submit malicious content into a vulnerable form field. Exploitation also requires a victim to browse to a page containing the stored payload.
Who is exposed to the malicious script?
Users who browse to a page containing the vulnerable field may have malicious JavaScript execute in their browser. The changed scope indicates the impact can extend beyond the permissions of the low-privileged attacker who injected the content.
Is this exploitable without user interaction?
No. Although the attacker can store the payload, a victim must browse to the page where the vulnerable field is rendered for the script to execute.