Impact
Adobe Experience Manager is affected by a DOM-based Cross‑Site Scripting flaw that allows an attacker to manipulate the browser’s Document Object Model to inject and execute malicious JavaScript. The vulnerability requires a victim to visit a crafted web page, after which arbitrary script can run with the same privileges as the victim’s session, potentially leading to credential theft, session hijacking, or defacement. The description indicates a change of scope, signifying that the attacker might gain additional privileges within the application context, but the flaw remains client‑side and does not provide remote code execution on the server.
Affected Systems
Adobe Experience Manager 6.5, Adobe Experience Manager 6.5 LTS, and Adobe Experience Manager as a Cloud Service are the affected products covered by the advisory.
Risk and Exploitability
The CVSS score of 5.4 classifies the severity as medium; no EPSS score is available and the vulnerability is not listed in the CISA KEV catalog, suggesting a lower likelihood of widespread exploitation. The primary attack vector requires user interaction through a crafted webpage, meaning that unsolicited attacks are less probable. Nonetheless, the potential for the attacker to inject malicious code into a victim’s browser and the possible scope elevation warrant immediate attention.
OpenCVE Enrichment