Impact
Adobe Experience Manager is affected by a DOM-based Cross‑Site Scripting (XSS) flaw. The vulnerability allows an attacker to inject malicious JavaScript into a victim’s browser when the victim visits a crafted page. This flaw is a classic input handling weakness (CWE-79) and can be used to run arbitrary code in the context of the user’s browser session, potentially impacting confidentiality, integrity, or availability of information accessed in that session. The CVE notes that exploitation requires user interaction and that the scope of the vulnerability is changed in the affected environment.
Affected Systems
Adobe Experience Manager versions 6.5, 6.5 LTS, and the Cloud Service edition are impacted. No specific patch versions are listed in the advisory; administrators should refer to the Adobe Security Advisory and ensure they are running any released patch or the latest supported version of the product.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate severity, and exploitation requires user interaction because the victim must visit a crafted page. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog, suggesting a lower likelihood of widespread exploitation. Nonetheless, the potential impact warrants a timely response.
OpenCVE Enrichment