Impact
Adobe Experience Manager versions 6.5.24, FP11.7 and earlier contain a DOM‑based Cross‑Site Scripting vulnerability that allows an attacker to inject malicious JavaScript executed in the victim’s browser. When a user visits a crafted page, the attacker‑controlled code runs with the victim’s privileges, potentially enabling session hijacking, data theft or other malicious actions performed in the context of the user’s session.
Affected Systems
The affected product is Adobe Experience Manager. All releases up through version 6.5.24 and Pulse Fix 11.7, as well as earlier releases, are vulnerable. Systems running a later release are not known to be impacted.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate severity, and no EPSS data or KEV listing is available. Exploitation requires user interaction with a maliciously crafted webpage; delivery could occur through email links, social engineering or compromised content. While the vulnerability does not provide remote code execution on the server, it undermines the confidentiality and integrity of the victim’s session and data and thus represents a moderate risk under the current circumstances.
OpenCVE Enrichment