Impact
Adobe Experience Manager is vulnerable to a DOM-based Cross‑Site Scripting flaw that lets an attacker inject malicious JavaScript into the page by manipulating the Document Object Model. This can cause the victim’s browser to run arbitrary code, potentially stealing credentials, hijacking sessions, or defacing the site. The weakness is classified as CWE‑79. The vulnerability’s description notes that the scope is changed, meaning the flaw could affect other system resources beyond the immediate context of the exploited page.
Affected Systems
Adobe Experience Manager 6.5, Adobe Experience Manager 6.5 LTS, and Adobe Experience Manager as a Cloud Service are reported to be affected. The advisory does not list sub‑versions, so any release of these products may be vulnerable until a patch is applied.
Risk and Exploitability
The CVSS score of 5.4 places this flaw in the intermediate severity range, and the EPSS score of less than 1% indicates a very low likelihood of exploitation. It is not currently listed in the CISA KEV catalog. Exploitation requires user interaction – a victim must open a crafted webpage – and the vulnerability does not appear to grant broader privileges beyond the user’s session. The scope change suggests possible impact on other resources, but no privilege escalation beyond the victim user is described in the information provided.
OpenCVE Enrichment