Impact
Adobe Experience Manager is vulnerable to a DOM‑based Cross‑Site Scripting flaw. An attacker can manipulate the Document Object Model to inject and run malicious JavaScript in the context of a user’s browser. Because the flaw operates entirely in the client browser, a victim must visit a crafted page for exploitation. The attack can expose sensitive data or hijack user sessions within the application domain.
Affected Systems
The flaw affects Adobe Experience Manager versions 6.5 and 6.5 LTS, as well as the Experience Manager as a Cloud Service offering. All affected releases are listed in the Adobe advisory.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate severity. The EPSS score is not available, and the vulnerability is not in the CISA KEV catalog. Exploitation requires user interaction: a malicious link or embedded script must be visited or clicked by the target. The scope change indicates that the vulnerability is confined to the application’s local context, but the impact remains a client‑side code execution that an attacker can exploit on any authenticated or unauthenticated user who follows the crafted URL.
OpenCVE Enrichment