Impact
Adobe Experience Manager is affected by a DOM‑based Cross‑Site Scripting vulnerability that allows an attacker to inject and execute malicious JavaScript within a victim’s browser. The flaw requires the victim to visit a crafted webpage, after which the attacker can influence the DOM environment. The impact includes potential data theft, session hijacking, or defacement, as the script runs under the user’s privileges. The CVE notes that the scope is changed, indicating that the vulnerability might affect resources beyond the immediate user context.
Affected Systems
Adobe Experience Manager versions 6.5 and 6.5 LTS, and Adobe Experience Manager as a Cloud Service are affected. The vulnerability applies to all deployments of these products regardless of environment.
Risk and Exploitability
The CVSS score of 5.4 rates the issue as moderate severity, and the EPSS score of less than 1 % implies a very low probability of exploitation at present. The vulnerability is not listed in the CISA KEV catalog, further suggesting limited current exploitation activity. Exfiltration of data or defacement could result, but since the flaw requires user interaction with a crafted page, it is not remotely exploitable without an initial social engineering step. The noted scope change signals that a successful exploit could potentially cross privilege boundaries, but the overall risk remains moderate.
OpenCVE Enrichment