Impact
A DOM‑based cross‑site scripting flaw allows an attacker to manipulate the document Object Model of a victim’s browser and execute arbitrary JavaScript within that browser context. The code runs with the same privileges as the victim’s session, potentially enabling any client‑side action that the browser permits. The vulnerability is confined to the web application layer and does not compromise server or system resources directly.
Affected Systems
Adobe Experience Manager 6.5, Adobe Experience Manager 6.5 LTS, and the Adobe Experience Manager as a Cloud Service edition are listed as affected. No other products or versions are mentioned in the advisory.
Risk and Exploitability
The CVSS score of 5.4 categorises the flaw as medium severity. The EPSS score is not provided, so no estimate of current exploitation probability is available. The vulnerability is not present in the CISA Known Exploited Vulnerability catalog. Exploitation requires the victim to visit a specially crafted web page, indicating that successful attacks depend on user interaction. The scope is reported as changed, but no additional impact beyond the browser context is described in the advisory.
OpenCVE Enrichment