Stored Cross-Site Scripting Vulnerability in Adobe Experience Manager
CVE-2025-47091
5.4MEDIUM
What is CVE-2025-47091?
Adobe Experience Manager versions 6.5.22 and earlier are subject to a stored Cross-Site Scripting vulnerability. This flaw allows low-privileged attackers to inject harmful scripts into vulnerable form fields. When a user interacts with the affected page, the injected JavaScript can be executed in their browser, potentially leading to unauthorized access to sensitive information or user sessions.
Affected Version(s)
Adobe Experience Manager 0 <= 6.5.22