Impact
Adobe Experience Manager is vulnerable to a DOM‑based cross‑site scripting flaw that allows an attacker to inject and execute arbitrary JavaScript in the victim’s browser; the vulnerability requires the victim to visit a crafted webpage, and it involves a change in scope.
Affected Systems
Adobe Experience Manager 6.5, Adobe Experience Manager 6.5 LTS, and Adobe Experience Manager as a Cloud Service are affected; the impact is confined to the web applications served by these products.
Risk and Exploitability
The CVSS v3.1 score of 5.4 indicates moderate severity, and the EPSS score of less than 1 % shows a very low current exploitation probability. The description notes that the vulnerability changes scope, which could broaden the reach within the application, and the flaw is not listed in the CISA KEV catalog. Exploitation still requires user interaction, making it primarily a client‑side threat that could be mitigated by standard defense‑in‑depth controls, though legitimate exposure is possible via phishing or malicious links.
OpenCVE Enrichment