Impact
Adobe Experience Manager is affected by a DOM‑based Cross‑Site Scripting vulnerability that allows an attacker to inject and execute malicious JavaScript in the victim's browser. The flaw requires that a user visit a crafted page, with the attacker manipulating the document object model to override client‑side logic. Once executed, the attacker can read or modify page contents, steal session cookies, or perform actions on behalf of the user, thereby violating confidentiality and integrity in a client‑side context.
Affected Systems
Adobe Experience Manager 6.5, 6.5 LTS, and the Cloud Service edition are all affected. Specific patched versions are not listed in the data, so any installation of these editions should consider applying the Adobe Security Bulletin APSB26‑98 fix.
Risk and Exploitability
The CVSS score of 5.4 indicates a moderate impact risk. EPSS data is not available, and the vulnerability is not listed in the KEV catalog, suggesting no widespread current exploitation. The attack vector is client‑side and requires user interaction – the victim must visit a maliciously crafted URL or click a link. Exploitation would likely occur through social engineering or by embedding the payload in a trusted domain that the user visits.
OpenCVE Enrichment