Stored Cross-Site Scripting Vulnerability in Adobe Experience Manager
CVE-2025-64620
5.4MEDIUM
What is CVE-2025-64620?
Adobe Experience Manager versions 6.5.23 and earlier are vulnerable to a stored Cross-Site Scripting (XSS) flaw that allows low privileged attackers to inject malicious JavaScript into vulnerable form fields. When an unsuspecting user interacts with the compromised fields, the malicious scripts could execute in the user's browser, leading to potential data theft or session hijacking.
Affected Version(s)
Adobe Experience Manager 0 <= 6.5.23