Impact
Adobe Experience Manager is vulnerable to a DOM‑based Cross‑Site Scripting flaw that allows an attacker to manipulate the environment of a victim’s browser and execute arbitrary client‑side JavaScript. The flaw requires the victim to load a specially crafted web page and the vulnerability’s scope is changed, indicating that the impact can extend beyond the original request origin.
Affected Systems
The affected products are Adobe Experience Manager 6.5, Adobe Experience Manager 6.5 LTS, and Adobe Experience Manager as a Cloud Service. No specific modified product versions were disclosed in the public advisory, so any deployment of the listed products could be at risk.
Risk and Exploitability
The CVSS score of 5.4 indicates a moderate severity. Because the exploit requires victim interaction to visit a malicious page, the probability of exploitation is not quantified due to lack of an EPSS score, and the vulnerability is not listed in CISA’s KEV catalog. The risk to an organization depends on the presence or absence of mitigations such as input sanitisation or client‑side controls.
OpenCVE Enrichment