CVE-2025-54251

Published Sep 9, 2025

Last updated 18 days ago

CVSS medium 4.3
Adobe Experience Manager

Overview

AI description

Automated description summarized from trusted sources.

CVE-2025-54251 affects Adobe Experience Manager versions 6.5.23.0 and earlier. It is classified as an XML Injection vulnerability. A low-privileged attacker could exploit this vulnerability to manipulate XML queries. This could lead to a security feature bypass. Successful exploitation of CVE-2025-54251 could allow an attacker to gain limited unauthorized write access. The vulnerability stems from the software's failure to properly neutralize special elements used in XML, which allows modification of the XML syntax, content, or commands before processing.

Description
Adobe Experience Manager versions 6.5.23.0 and earlier are affected by an XML Injection vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to manipulate XML queries and gain limited unauthorized write access.
Source
psirt@adobe.com
NVD status
Analyzed
Products
experience_manager

Risk scores

CVSS 3.1

Type
Primary
Base score
4.3
Impact score
1.4
Exploitability score
2.8
Vector string
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Severity
MEDIUM

Weaknesses

psirt@adobe.com
CWE-91

Social media

Hype score
Not currently trending

Configurations