Impact
Adobe Experience Manager contains a DOM‑based Cross‑Site Scripting flaw that allows an attacker to inject and execute malicious JavaScript within a victim’s browser. The vulnerability is triggered when a user loads a specially crafted URL or webpage that manipulates the page’s DOM. Because the execution occurs client‑side, the attacker gains control of the browser context without altering any server‑side data.
Affected Systems
Products affected are Adobe Experience Manager 6.5, 6.5 LTS, and the Adobe Experience Manager as a Cloud Service offering. Administrators should ensure that all installations are updated to the latest release level covered by the advisory linked in the reference.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate severity. No EPSS data is available, so the current likelihood of exploitation is uncertain. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires user interaction, typically by visiting a maliciously crafted page or clicking a link that triggers the DOM manipulation. Successful exploitation would allow an attacker to run arbitrary JavaScript in the context of the victim’s session, potentially enabling further client‑side attacks.
OpenCVE Enrichment