Impact
Adobe Experience Manager is vulnerable to a DOM‑based Cross‑site Scripting flaw that allows an attacker to inject and execute malicious JavaScript in the victim’s browser context by manipulating the Document Object Model. The injected code runs with the privileges of the authenticated user, potentially enabling session hijacking, data theft, or other malicious actions that compromise confidentiality and integrity of user data. The vulnerability requires that a victim visit a specially crafted web page, meaning a social‑engineering component is required for exploitation.
Affected Systems
All instances of Adobe Experience Manager version 6.5, including 6.5 LTS and the Cloud Service deployment, are affected. No more granular version information is provided.
Risk and Exploitability
The CVSS score of 5.4 indicates a moderate severity. No EPSS score is available and the issue is not listed in the CISA KEV catalog, suggesting it is not currently exploited in the wild. Exploitation requires user interaction and relies on the attacker delivering a crafted URL or web page; the vulnerability’s scope change implies that an attacker could potentially affect other application components if successful. Given the moderate score and the need for victim interaction, the likely attack vector is a malicious link or socially engineered bait. The overall risk is moderate but should be mitigated promptly to prevent potential data exposure.
OpenCVE Enrichment