Impact
The vulnerability is a DOM‑based Cross‑Site Scripting flaw in Adobe Experience Manager. An attacker can craft a page and force a victim’s browser to execute arbitrary JavaScript. The flaw requires user interaction and can change the security scope of the affected environment.
Affected Systems
Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected. All installations of the aforementioned releases running on any supported platform are at risk.
Risk and Exploitability
The CVSS score of 5.4 suggests a moderate severity. No EPSS score is reported, making it unclear how frequently this flaw is exploited in the wild. The flaw is not listed in CISA’s KEV catalog, indicating limited known exploitation. The likely attack vector is a user visiting a crafted URL, after which malicious script runs in the victim’s browser.
OpenCVE Enrichment