Impact
Adobe Experience Manager is vulnerable to a DOM‑based Cross‑Site Scripting flaw that permits an attacker to inject and run malicious JavaScript in the victim’s browser context. The vulnerability escalates privileges within the application scope, potentially allowing session hijacking, data theft, or the execution of arbitrary client‑side scripts, but it does not grant direct server‑side code execution.
Affected Systems
The flaw affects Adobe Experience Manager 6.5, Adobe Experience Manager 6.5 LTS, and the Adobe Experience Manager as a Cloud Service offering. No specific version numbers beyond these product releases are listed, so all instances of these products may be impacted until a patch is applied.
Risk and Exploitability
The CVSS score of 5.4 indicates a moderate severity, and the absence of EPSS data means the likelihood of exploitation is not quantifiable at present. The vulnerability requires user interaction – a crafted webpage must be accessed by a victim – which reduces spontaneous exploitation potential. As of this analysis the flaw is not listed in the CISA KEV catalog, implying no publicly known exploits are documented, though the scope change may allow privilege escalation within the application. Accordingly the risk is moderate but could increase should a vendor patch be delayed or if the flaw is leveraged in targeted attacks.
OpenCVE Enrichment