Impact
Adobe Experience Manager is vulnerable to a DOM-based Cross‑Site Scripting flaw that allows an attacker to inject and execute arbitrary JavaScript in the victim’s browser. The vulnerability relies on manipulating the DOM environment via a crafted page and requires that the user visit that page. Scope is changed.
Affected Systems
The flaw affects Adobe Experience Manager 6.5, Adobe Experience Manager 6.5 LTS, and Adobe Experience Manager as a Cloud Service. Users of any of these versions should verify that their installations are running the patched release referenced in Adobe APSB26‑74.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate overall severity. The EPSS of less than 1% suggests a very low likelihood of widespread exploitation at present, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector involves a crafted webpage that the victim must visit, triggering JavaScript execution in the browser context of the trusted Adobe Experience Manager domain.
OpenCVE Enrichment