Impact
Adobe Experience Manager is vulnerable to a DOM‑based Cross‑Site Scripting flaw that enables an attacker to execute arbitrary JavaScript in a victim’s browser. The flaw originates from improper handling of user‑supplied data within the Document Object Model. Exploitation of this weakness requires user interaction, typically by visiting a malicious web page crafted to manipulate the DOM environment. The impact encompasses confidentiality, integrity, and availability of the user session, as well as the potential to deface content or exfiltrate data. The underlying weakness is identified as CWE‑79.
Affected Systems
Adobe Experience Manager 6.5, Adobe Experience Manager 6.5 LTS, and Adobe Experience Manager as a Cloud Service are affected. Users of these products across all supported versions must verify their deployment version and consider the advisory.
Risk and Exploitability
The risk is moderate with a CVSS score of 5.4. EPSS information is not available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a victim interacting with a crafted URL or webpage. Successful exploitation would result in malicious script execution within the victim’s browser context under the application’s domain.
OpenCVE Enrichment