Stored Cross-Site Scripting Vulnerability in Adobe Experience Manager
CVE-2025-47041
5.4MEDIUM
What is CVE-2025-47041?
Adobe Experience Manager, especially versions 6.5.22 and earlier, is vulnerable to a stored Cross-Site Scripting (XSS) flaw. This vulnerability allows an attacker with low privileges to inject harmful scripts into the application’s form fields. When a user interacts with these fields, the malicious JavaScript can be executed in their browser, potentially leading to session hijacking or other malicious exploits. It is crucial for users to assess their instances of Adobe Experience Manager and apply necessary security measures.
Affected Version(s)
Adobe Experience Manager 0 <= 6.5.22