Stored Cross-Site Scripting Vulnerability in Adobe Experience Manager
CVE-2025-46954
5.4MEDIUM
What is CVE-2025-46954?
Adobe Experience Manager versions 6.5.22 and earlier contain a stored Cross-Site Scripting (XSS) vulnerability that can be exploited by low-privileged attackers. This flaw allows the injection of malicious scripts into susceptible form fields, potentially leading to the execution of harmful JavaScript in the browser of users who interact with the affected content. It underscores the importance of promptly addressing security flaws to mitigate risks associated with client-side script execution.
Affected Version(s)
Adobe Experience Manager 0 <= 6.5.22