Impact
Adobe Experience Manager is affected by a DOM‑based Cross‑Site Scripting vulnerability that allows an attacker to inject malicious JavaScript into a victim’s browser. An attacker can do this by crafting a web page that, when visited by a user, modifies the Document Object Model and executes the attacker’s script. The impact is limited to the victim’s browser session; it can enable session hijacking, data theft, or additional malware delivery, but it does not give direct control over the server or other users.
Affected Systems
The vulnerability applies to Adobe Experience Manager 6.5, Adobe Experience Manager 6.5 LTS, and the Adobe Experience Manager as a Cloud Service. No specific sub‑versions are listed, so all releases of these products are considered affected unless a patch has been applied.
Risk and Exploitability
The CVSS score of 5.4 classifies the vulnerability as moderate. Because exploitation requires a user to visit a crafted page, it is an interactive, client‑side attack and the EPSS score is unavailable. The vulnerability is not listed in CISA’s KEV catalog. The attack path therefore depends on social engineering or malicious links, making it a moderate risk that can be mitigated by applying the vendor’s security update.
OpenCVE Enrichment