Impact
Adobe Experience Manager is affected by a DOM‑based Cross‑Site Scripting vulnerability. An attacker can craft a malicious webpage that causes a victim’s browser to execute arbitrary JavaScript through manipulation of the DOM. This flaw allows the execution of code in the context of the victim’s browser session and can lead to the compromise of sensitive data or the execution of unauthorized actions within the scope of the victim's privileges. The issue requires the victim to load a crafted page, so it is user‑interaction dependent.
Affected Systems
Affected products include Adobe Experience Manager 6.5, Adobe Experience Manager 6.5 LTS, and Adobe Experience Manager as a Cloud Service, as listed by Adobe.
Risk and Exploitability
The CVSS score of 5.4 places this flaw in the medium severity range. No EPSS data is available, indicating that a precise exploitation probability has not been quantified. The vulnerability is not listed in the CISA KEV catalog. Because exploitation requires the victim to visit a crafted page, the attack vector is likely a malicious link or embedded content that manipulates the DOM. Overall, the risk is moderate and can be mitigated effectively through timely patching and application hardening.
OpenCVE Enrichment