Adobe Experience Manager Forms JEE versions LTS SP1, 6.5.24.0 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field, potentially gaining elevated access or control over the victim's account or session. Scope is changed.
The vulnerability consists of insufficient input sanitization in form fields of the AEM Forms JEE application. An unauthenticated attacker, but requiring user interaction (UI:R), injects malicious JavaScript into a vulnerable form field, where it is permanently stored (stored XSS). When the victim visits the page containing the infected field, the script is automatically executed in their browser within the application context. The scope change means that the effects extend beyond the vulnerable component itself.
An attacker can execute arbitrary JavaScript code in the victim's browser, enabling session hijacking, credential theft, privilege escalation, or takeover of user accounts. The high impact on confidentiality and integrity makes this threat particularly serious in corporate environments handling sensitive forms.
Patches available from the vendor should be applied according to references — the official Adobe security bulletin is available at: https://helpx.adobe.com/security/products/aem-forms/apsb26-57.html
Adobe Experience Manager Forms JEE in LTS SP1 version, 6.5.24.0 and earlier versions
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:NAdobe Experience Manager
APPAdobe6.5≤ 6.5.24.0Apple iOS
OSAppleall versionsApple macOS
OSAppleall versionsGoogle Android
OSGoogleall versionsLinux Kernel
OSLinuxall versionsMicrosoft Windows
OSMicrosoftall versions
Related vulnerabilities
Pominięcie uwierzytelniania w Screen Sharing na macOS
Atak na łańcuch dostaw DAEMON Tools Lite — trojanizacja instalatorów
Type confusion w V8 (Google Chrome) — zdalne uszkodzenie sterty
Apple iOS/iPadOS/macOS — out-of-bounds write przy przetwarzaniu obrazu
Commvault Command Center – nieuwierzytelniony RCE przez path traversal w ZIP