Impact
A DOM‑based Cross‑Site Scripting vulnerability exists in Adobe Experience Manager. An attacker can manipulate the browser’s DOM environment by directing a victim to a malicious URL, causing arbitrary JavaScript to execute within the victim’s browser context. The attack requires user interaction and changes the scope of the vulnerability.
Affected Systems
Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier.
Risk and Exploitability
The CVSS score of 5.4 indicates a moderate severity. EPSS data is not available and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires a victim to visit a crafted webpage; the typical attack vector is a malicious link or embedded content that induces the victim’s browser to parse and execute script via the DOM.
OpenCVE Enrichment