Impact
A DOM‑based Cross‑Site Scripting flaw exists in Adobe Experience Manager that allows an attacker to embed malicious JavaScript into a page viewed by a victim. The attacker must create a crafted URL or webpage that manipulates the Document Object Model of the victim’s browser, causing the browser to execute the attacker’s script in the context of the site. Exploitation requires the victim to visit the crafted page, and the scope of the vulnerability is marked as changed, indicating that the malicious code will run as if it were part of the legitimate application.
Affected Systems
Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate severity. No EPSS score is reported, and the vulnerability is not listed in the CISA KEV catalog, suggesting it has not yet been widely exploited. The likely attack vector requires active user interaction—an attacker must convince a victim to visit a malicious page that triggers the DOM manipulation. Given the moderate score and lack of evidence of active exploitation, the risk is considered moderate but should be mitigated promptly.
OpenCVE Enrichment