Impact
Adobe Experience Manager is affected by a DOM‑based Cross‑Site Scripting vulnerability that enables an attacker to inject and execute malicious JavaScript within the victim’s browser by manipulating the Document Object Model. The flaw requires user interaction: a victim must visit a specially crafted webpage for exploitation to occur. The advisory notes that the scope is changed, but no further detail is provided about the extent of that change.
Affected Systems
Adobe Experience Manager 6.5, Adobe Experience Manager 6.5 LTS, and Adobe Experience Manager operated as a Cloud Service are all impacted. Specific version numbers that include the fix are not listed, so administrators should refer to the Adobe security advisory for accurate patch information.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate severity. The EPSS score is less than 1 %, suggesting a very low probability of exploitation at present. The vulnerability is not in the CISA KEV catalog. Exploitation requires a victim to knowingly or unknowingly visit a crafted URL, so the attack vector is purely client‑side. The mention of a changed scope implies that additional impact could arise beyond the local user context, but the CVE description does not elaborate further.
OpenCVE Enrichment