Impact
A DOM‑based Cross‑Site Scripting (XSS) flaw in Adobe Experience Manager allows an attacker to manipulate the DOM environment and run malicious JavaScript when a victim visits a crafted webpage. This vulnerability changes the scope of the application’s execution context, enabling the attacker to execute code within the victim’s browser session without requiring additional permissions.
Affected Systems
Adobe Experience Manager 6.5, Adobe Experience Manager 6.5 LTS, and the Adobe Experience Manager as a Cloud Service are all affected by this issue. No specific sub‑versions are listed, so all releases under these product lines are potentially vulnerable until a patch is applied.
Risk and Exploitability
The CVSS score of 5.4 indicates a moderate severity. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires user interaction – the victim must click or load a specially crafted URL. Once the victim’s browser processes the page, the malicious JavaScript runs with the privileges of the authenticated session, potentially stealing credentials, modifying page content or redirecting traffic. Given the lack of remote code execution beyond the browser context and the need for user interaction, the risk is considered moderate, but the impact on a compromised user can be significant.
OpenCVE Enrichment