Impact
Adobe Experience Manager is vulnerable to a DOM-based Cross-site Scripting flaw that allows an attacker to inject and execute malicious JavaScript within the context of a victim's browser. The exploit requires the victim to visit a crafted webpage, after which the attacker can manipulate the Document Object Model to run arbitrary code. Scope is changed, meaning the vulnerability can affect all authenticated and unauthenticated users who view the affected resources.
Affected Systems
The affected products are Adobe Experience Manager 6.5, Adobe Experience Manager 6.5 LTS, and Adobe Experience Manager as a Cloud Service. Exact version details beyond the product names are not provided, but all releases under these designations are impacted.
Risk and Exploitability
The CVSS score of 5.4 indicates a medium severity level. The EPSS score is not available, and the vulnerability is not listed in CISA KEV. The likely attack vector is user interaction, requiring a victim to open a maliciously crafted URL. Exploitation could lead to the execution of arbitrary script in the victim’s browser, potentially compromising session data or defacing content. Given the medium score and required user action, the overall risk is moderate for environments where the affected software is exposed to untrusted web traffic.
OpenCVE Enrichment