Impact
Adobe Experience Manager is affected by a DOM-based Cross-site Scripting vulnerability that allows an attacker to manipulate the DOM and execute malicious JavaScript within the victim’s browser. This can lead to theft of user credentials, session hijacking, or unauthorized data access. The flaw is a CWE‑79 vulnerability and requires user interaction, as the victim must visit a crafted webpage. The scope is changed, indicating the issue may impact resources beyond the local context.
Affected Systems
Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are vulnerable. All releases prior to 6.5.25, including the long‑term support SP1 and earlier 2026.04 builds, are affected.
Risk and Exploitability
The CVSS score of 5.4 denotes a moderate risk. EPSS data are not available and the vulnerability is not listed in CISA KEV catalog. Exploitation requires the victim to visit a malicious page, making it a self-service attack that depends on user interaction. While the lack of an EPSS rating suggests a low to moderate exploit probability, the scope change and potential for session hijacking still warrant prompt attention.
OpenCVE Enrichment