Impact
Adobe Experience Manager is vulnerable to a DOM‑based Cross‑Site Scripting flaw that allows an attacker to insert and execute malicious JavaScript inside a victim’s browser. The vulnerability arises when user input or crafted URLs manipulate the DOM environment through the web application. Because the flaw is client‑side, exploitation requires the user to click or navigate to a specially constructed web page, after which the attacker can run arbitrary script with the victim’s browser context. This can lead to theft of session cookies, unauthorized actions performed on behalf of the user, or the delivery of additional malware.
Affected Systems
The affected products are Adobe Experience Manager 6.5, Adobe Experience Manager 6.5 LTS, and Adobe Experience Manager as a Cloud Service. No specific patch level or version numbers are listed in the CNA data, so users should verify that their deployments include the latest Adobe security release for these releases.
Risk and Exploitability
The CVSS score of 5.4 indicates a moderate severity vulnerability. The EPSS score is not available and the issue is not listed in the CISA KEV catalog, suggesting it is not a widely exploited or actively targeted vulnerability. Because the attack vector needs user interaction and occurs client‑side, the likelihood of exploitation is lower than a server‑side flaw, but the impact remains significant if users are tricked into visiting a malicious page. The ‘Scope is changed’ tag signals that the flaw may affect more components than initially scoped, reinforcing the need for remediation.
OpenCVE Enrichment