Impact
Adobe Experience Manager is vulnerable to a DOM‑based Cross‑Site Scripting flaw that would allow an attacker to inject and execute malicious JavaScript in the victim’s browser. The flaw arises from unsafe manipulation of the Document Object Model and can lead to defacement, phishing or the execution of other malicious code within the user’s session. The vulnerability is classified as a medium‑severity defect with a CVSS score of 5.4, indicating a moderate impact on confidentiality, integrity, or availability.
Affected Systems
The affected products are Adobe Experience Manager 6.5, Adobe Experience Manager 6.5 LTS, and Adobe Experience Manager as a Cloud Service. Any instance of these editions that has not applied the latest security update is susceptible to the DOM‑based XSS flaw.
Risk and Exploitability
The likely attack vector requires a victim to visit a crafted web page containing malicious input that triggers the DOM manipulation. No remote code execution or privilege escalation is possible beyond the victim’s own browser context. With a moderate CVSS score and no EPSS data, the likelihood of exploitation is considered low to moderate, and the vulnerability is not currently listed in CISA’s KEV catalog. The risk to operational continuity remains low, but the potential for user‑focused attacks such as phishing or credential theft warrants timely mitigation.
OpenCVE Enrichment