Impact
Adobe Experience Manager is vulnerable to a DOM‑based XSS flaw that allows an attacker to execute arbitrary JavaScript within a victim’s browser by manipulating the DOM environment. The exploitation requires a victim to click a crafted link or open a malicious page, and the flaw can change the scope of affected components, potentially enabling elevated privileges for the malicious code.
Affected Systems
The affected products are Adobe Experience Manager 6.5, its 6.5 LTS edition, and the Experience Manager as a Cloud Service incarnation.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate severity. EPSS data is not available, so the exact likelihood of exploitation is unclear, though the vulnerability is easy to trigger and not listed in the CISA KEV catalog. The attack vector is user interaction, typically a crafted link, and the scope change suggests that the vulnerability could impact multiple system components if exploited.
OpenCVE Enrichment