Impact
Adobe Experience Manager is vulnerable to a DOM‑based Cross‑Site Scripting flaw. The defect permits an attacker to manipulate the Document Object Model in the victim’s browser and run malicious JavaScript, potentially compromising secrets, local data, or performing phishing attacks within the user’s session. The flaw is a classic input‑validation weakness, reflected in CWE‑79, and requires that the victim visit a specially crafted web page to trigger the flaw.
Affected Systems
Affected products include Adobe Experience Manager 6.5, the 6.5 LTS release, and the Adobe Experience Manager as a Cloud Service offering. Users operating these versions or hosting instances of the product are susceptible if no remedial update has been applied.
Risk and Exploitability
The CVSS score of 5.4 indicates a moderate severity. The EPSS value is not available, and the vulnerability is not listed in CISA’s KEV catalog. Exploitation mandates user interaction; an attacker must entice a user to open a crafted URL. The attack surface is the client browser, and successful exploitation can lead to the execution of arbitrary JavaScript within the context of the victim’s session. Attackers could thereby steal session tokens or perform actions on behalf of the user, but major privilege escalation is not possible at the application layer.
OpenCVE Enrichment