Impact
Adobe Experience Manager versions 6.5.24, LTS SP1 and 2026.04 and earlier contain a DOM‑based Cross‑Site Scripting vulnerability (CWE‑79). By manipulating the DOM, an attacker can cause malicious JavaScript to execute inside the victim’s browser context when the victim visits a specially crafted page. The flaw does not allow remote code execution outside of the browser, and it requires that the user interact with the site to trigger the exploit.
Affected Systems
The affected product is Adobe Experience Manager. Vulnerable releases include 6.5.24, the LTS Service Pack 1 and update 2026.04, as well as any earlier releases in that series.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate severity. No EPSS information is available and the issue is not listed in CISA’s KEV catalog. Exploitation requires the victim to load a crafted web page, so the attack vector is limited to social engineering or phishing. Once the victim’s browser runs the injected script, the attacker could perform actions in the victim’s context, but the description does not state any specific additional impact such as data theft.
OpenCVE Enrichment