Impact
This vulnerability allows the execution of arbitrary JavaScript within the victim’s browser by manipulating the DOM environment. The attacker can only succeed if the user visits a specially crafted web page, after which the malicious script runs with the user’s browser privileges, enabling actions such as data theft or session hijacking.
Affected Systems
Adobe Experience Manager versions 6.5.24, FP11.7 and all earlier releases are affected. The product is Adobe Experience Manager provided by Adobe.
Risk and Exploitability
The CVSS base score of 5.4 indicates a moderate severity. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires user interaction in the browser, so the attack vector is client‑side. While no exploit information is present in the provided data, the requirement of user interaction limits the ease of attack but still poses a risk to users who may unintentionally visit malicious content.
OpenCVE Enrichment