Impact
Adobe Experience Manager is affected by a DOM‑based Cross‑Site Scripting (XSS) vulnerability that allows an attacker to manipulate the DOM environment and execute malicious JavaScript in the victim’s browser. Exploitation requires the victim to visit a crafted webpage. The impact can include hijacking user sessions, stealing credentials, or performing unauthorized actions on the site within the victim’s access level; these consequences are inferred from the typical effects of XSS. The CVE description indicates that the scope is changed, which suggests that the impact extends beyond the original boundaries but does not describe additional server‑side effects.
Affected Systems
The vulnerability affects Adobe Experience Manager 6.5, Adobe Experience Manager 6.5 LTS, and Adobe Experience Manager as a Cloud Service. All installations of these products are included in the scope of the advisory.
Risk and Exploitability
The CVSS score of 5.4 indicates a moderate level of risk. EPSS data is not available, and the issue is not listed in the CISA KEV catalog, suggesting no publicly known exploits. Because the attack requires user interaction and is limited to the client browser, the likelihood of widespread exploitation is lower than high‑severity vulnerabilities, though malicious third parties could still target high‑value users.
OpenCVE Enrichment