CVE-2025-27205

Adobe Experience Manager Screens versions FP11.3 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. Exploitation of this issue requires user interaction in that a victim must open a malicious link.
Configurations

Configuration 1 (hide)

cpe:2.3:a:adobe:experience_manager_screens:*:*:*:*:-:*:*:*

History

05 Aug 2025, 15:59

Type Values Removed Values Added
CPE cpe:2.3:a:adobe:experience_manager_screens:*:*:*:*:-:*:*:*
References () https://helpx.adobe.com/security/products/aem-screens/apsb25-32.html - () https://helpx.adobe.com/security/products/aem-screens/apsb25-32.html - Vendor Advisory
First Time Adobe experience Manager Screens
Adobe

09 Apr 2025, 20:03

Type Values Removed Values Added
Summary
  • (es) Las versiones FP11.3 y anteriores de Adobe Experience Manager Screens se ven afectadas por una vulnerabilidad de Cross-Site Scripting (XSS) almacenado que un atacante con pocos privilegios podría aprovechar para inyectar scripts maliciosos en campos de formulario vulnerables. JavaScript malicioso puede ejecutarse en el navegador de la víctima al acceder a la página que contiene el campo vulnerable. Para explotar este problema, la víctima debe abrir un enlace malicioso.

08 Apr 2025, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-08 18:15

Updated : 2025-08-05 15:59


NVD link : CVE-2025-27205

Mitre link : CVE-2025-27205

CVE.ORG link : CVE-2025-27205


JSON object : View

Products Affected

adobe

  • experience_manager_screens
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')