Impact
Adobe Experience Manager is vulnerable to a DOM‑based Cross‑Site Scripting flaw that allows an attacker to manipulate the DOM and execute arbitrary JavaScript in the victim’s browser when the victim visits a crafted page. This can compromise the confidentiality and integrity of the victim session, potentially enabling cookie theft, UI defacement, or other malicious actions. The vulnerability exploits unsanitized input in client‑side code and the impact is confined to the context of the interacting browser. Per the description, the attack requires the victim to load a malicious web page; no additional privileged conditions are attested.
Affected Systems
Adobe Experience Manager 6.5, including the 6.5 LTS release, and the Adobe Experience Manager as a Cloud Service offering are affected by the flaw. No further version granularity is provided beyond these product lines.
Risk and Exploitability
The CVSS score of 5.4 indicates a moderate risk level. The EPSS score is not available, so current exploitation likelihood cannot be quantified. The vulnerability is not listed in the CISA KEV catalog, and the attacker must obtain user interaction by visiting a malicious website. Because it is a client‑side DOM‑based XSS the exploitation scope is limited to the victim’s browser, but the lack of immediate mitigation could lead to moderate impact in environments where the affected Experience Manager instances are exposed to users.
OpenCVE Enrichment