Impact
Adobe Experience Manager is affected by a DOM‑based Cross‑Site Scripting vulnerability that allows an attacker to inject and execute malicious JavaScript in a victim's browser. The flaw requires the victim to load a crafted page, after which the attacker’s code runs in the context of the user, potentially stealing credentials, session tokens or performing actions on behalf of the user.
Affected Systems
The vulnerability impacts Adobe Experience Manager 6.5, Adobe Experience Manager 6.5 LTS, and Adobe Experience Manager as a Cloud Service. All installations of these products are affected unless the vendor’s security update (APSB26‑98) is applied.
Risk and Exploitability
With a CVSS score of 5.4 and no EPSS data, the risk is moderate, and the flaw has not been listed in the CISA KEV catalogue. Exploitation requires user interaction—an attacker must provide a link or embedded page that a victim visits, leading to execution of JavaScript in the victim’s browser. The scope change indicates that the vulnerability can affect the overall application behavior within the browser environment.
OpenCVE Enrichment