Impact
A DOM-based Cross-Site Scripting flaw allows an attacker to inject malicious JavaScript through the browser’s DOM environment. In the context of the victim’s browser, the injected code can read, modify or exfiltrate data, and can also launch additional malicious actions if the user interacts with the compromised content. The vulnerability is identified as CWE‑79 and affects how user data is rendered and manipulated on the page.
Affected Systems
Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are impacted. The flaw occurs in the processing of user‑controlled DOM elements within the CMS platform and any site built with these versions.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate severity. Because the exploit requires a victim to visit a crafted webpage, the attack vector is likely phishing or malicious link. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting no known widespread exploitation at this time. Still, the scope change indicates that the flaw can affect more components than initially assumed, raising the potential impact of an exploit.
OpenCVE Enrichment