Impact
Adobe Experience Manager is susceptible to a DOM-based Cross‑Site Scripting flaw, allowing an attacker to inject malicious JavaScript into a victim’s browser by manipulating the DOM environment. The vulnerability can alter the browser’s state and run arbitrary script at the same privilege level as the victim, which could lead to credential theft or session hijacking. The impacted CWE is 79. The issue requires user interaction: the target must visit a crafted webpage to trigger exploitation.
Affected Systems
Adobe Experience Manager versions 6.5, 6.5 LTS, and the Cloud Service are affected. No specific patch versions are listed in the data, but the affected products are all Adobe Experience Manager distributions.
Risk and Exploitability
The CVSS score of 5.4 indicates a moderate severity for this vulnerability. With an unknown EPSS score, the likelihood of exploitation in the wild cannot be quantified, and it is not present in the CISA KEV catalog. The evident attack vector is user‑initiated interaction with a maliciously crafted page, and the scope is altered. If exploited, an attacker can execute arbitrary JavaScript within the victim’s browser context, affecting confidentiality, integrity, and availability of the user session.
OpenCVE Enrichment