Stored Cross-Site Scripting Vulnerability in Adobe Experience Manager
CVE-2025-64598
5.4MEDIUM
What is CVE-2025-64598?
Adobe Experience Manager versions up to 6.5.23 are susceptible to a stored Cross-Site Scripting (XSS) vulnerability. This issue allows low-privileged attackers to inject malicious scripts into vulnerable form fields, leading to the potential execution of harmful JavaScript within the victim's browser when they access the compromised page. Affected users risk exposure to data theft, account takeover, or additional cyber threats unless mitigated.
Affected Version(s)
Adobe Experience Manager 0 <= 6.5.23