Impact
Adobe Experience Manager is affected by a DOM‑based Cross‑Site Scripting vulnerability that allows an attacker to manipulate the browser’s DOM environment to execute malicious JavaScript within the victim’s session. The flaw requires the victim to visit a crafted webpage, after which arbitrary code can run in the victim’s context, potentially leading to data theft, credential compromise or further session hijacking. The vulnerability changes the scope, which means the impact can extend beyond the initial context of the request.
Affected Systems
The affected product family is Adobe Experience Manager, specifically version 6.5, the 6.5 LTS release, and the Experience Manager as a Cloud Service offering. No additional version granularity is reported; all builds of these releases are considered vulnerable unless an update has been applied.
Risk and Exploitability
The CVSS base score of 5.4 indicates a medium severity rating, and the exploitation is dependent on user interaction – the attacker must lure a user to a crafted URL or page. The EPSS score is not available, and the issue is not listed in the CISA KEV catalog, suggesting there is no widespread exploitation yet. Attackers would likely employ phishing or compromised websites to target users, and the impact is limited to the browser context of the victim.
OpenCVE Enrichment