Impact
Adobe Experience Manager is vulnerable to a DOM‑based Cross‑Site Scripting flaw that allows an attacker to inject and execute arbitrary JavaScript in a victim’s browser. The attack requires the victim to interact with a crafted page; once the malicious code runs, it executes with the context of the victim's session within the browser. This vulnerability is client‑side and does not provide server‑side compromise, and the scope is reported as changed.
Affected Systems
Adobe Experience Manager 6.5, Adobe Experience Manager 6.5 LTS, and Adobe Experience Manager as a Cloud Service are affected. No additional patch or release numbers are listed, so all instances of these product lines are potentially vulnerable.
Risk and Exploitability
The CVSS score of 5.4 indicates a moderate severity. The EPSS score of < 1 % suggests a very low probability that the vulnerability will be widely exploited in the near term. The vulnerability is not listed in the CISA KEV catalog. Attackers would need to lure victims to a malicious URL; the flaw is client‑side and does not allow server‑side compromise. Scope is reported as changed, which may extend the impact beyond the initially affected scope, but the attack still requires user interaction and a web browser prone to executing malicious script.
OpenCVE Enrichment