Impact
Adobe Experience Manager is affected by a DOM‑based Cross‑Site Scripting flaw that allows an attacker to manipulate the DOM environment and execute malicious JavaScript within the victim’s browser. The vulnerability requires the victim to visit a specially crafted webpage, after which browser‑side code runs in the user’s context.
Affected Systems
Adobe Experience Manager versions 6.5, 6.5 LTS, and Adobe Experience Manager as a Cloud Service are affected. No specific patch or fixed version information is listed in the advisory.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate severity, while an EPSS score of less than 1% shows the exploit likelihood is low. The vulnerability is not listed in the CISA KEV catalog. Because the flaw requires the victim to voluntarily visit a crafted URL, the attack vector is user‑directed, which limits the rapidity of widespread exploitation.
OpenCVE Enrichment