Impact
Adobe Experience Manager 6.5, its LTS edition, and the Cloud Service are vulnerable to a DOM‑based Cross‑Site Scripting flaw identified as CWE‑79. An attacker can trick a victim into visiting a specially crafted web page that manipulates the Document Object Model and causes arbitrary JavaScript to run in the victim’s browser. The vulnerability requires user interaction and can change the scope of the application, allowing the injected script to execute as the victim’s user, potentially exposing or manipulating content within the exposed context.
Affected Systems
The affected systems are Adobe Experience Manager 6.5, Adobe Experience Manager 6.5 LTS, and Adobe Experience Manager as a Cloud Service. No specific sub‑version numbers are listed, so all current releases of these products are considered potentially impacted.
Risk and Exploitability
The CVSS score of 5.4 indicates a moderate severity. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, suggesting the exploitation risk is not yet confirmed at scale. The likely attack vector is social engineering or phishing, requiring the victim to click a malicious link. Because the flaw changes scope, exploitation could affect multiple components of the application but still requires user interaction.
OpenCVE Enrichment