Impact
The vulnerability is a DOM‑based Cross‑Site Scripting flaw that allows an attacker to inject and run malicious JavaScript in the victim’s browser. The attacker can control the JavaScript code by manipulating the Document Object Model (DOM) environment. This can lead to theft of user data, session hijacking, or execution of further attacks in the victim’s context. The weakness is a classic input handling flaw as identified by CWE-79.
Affected Systems
Adobe Experience Manager versions 6.5 and 6.5 LTS, and the Cloud Service edition are impacted. No specific minor version constraints are listed by Adobe, so any release within those product lines is potentially vulnerable.
Risk and Exploitability
The CVSS score is 5.4, indicating a moderate impact level. Exploitation requires user interaction—a victim must visit a crafted web page containing the malicious code. Because the attack vector is browser‑based and relies on user interaction, the likelihood of widespread automated exploitation is limited. The EPSS score is not available and Adobe is not listed in the CISA KEV catalog, which suggests there is no evidence of active exploitation in the wild as of the latest data. The attack vector is therefore likely to be opportunistic rather than widespread.
OpenCVE Enrichment