Impact
Adobe Experience Manager is vulnerable to a DOM‑based Cross‑Site Scripting flaw that allows an attacker to inject and run malicious JavaScript in a victim’s browser. The flaw arises because user‑supplied data is used to construct or modify the Document Object Model during page load. Successful exploitation allows arbitrary JavaScript execution in the victim’s browser.
Affected Systems
All versions of Adobe Experience Manager 6.5 and the 6.5 LTS release, as well as the Adobe Experience Manager as a Cloud Service platform, are impacted. Any deployment of these products that has not applied the latest security update is potentially vulnerable.
Risk and Exploitability
The vulnerability carries a CVSS score of 5.4, indicating a moderate severity that requires user interaction to trigger. No EPSS score is available, and the flaw is not listed in the CISA KEV catalog. Exploitation would involve a victim visiting a specially crafted URL or webpage, after which the manipulated DOM triggers execution of attacker‑controlled script. Defensive controls such as content‑security‑policy headers that restrict script sources can mitigate the risk, yet timely patching remains the most effective preventive measure.
OpenCVE Enrichment