Impact
Adobe Experience Manager is affected by a DOM-based Cross‑Site Scripting vulnerability that allows an attacker to execute malicious JavaScript in the victim's browser by manipulating the DOM environment. Exploitation requires the victim to visit a crafted webpage, and the flaw changes the scope of the affected context, enabling the attacker to perform actions in the context of the authenticated user. The impact is the potential compromise of session data, credential theft, or the execution of additional malicious payloads.
Affected Systems
Adobe Experience Manager versions 6.5, 6.5 LTS, and the Adobe Experience Manager as a Cloud Service are affected.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate severity, and the EPSS score is not available, suggesting low to moderate exploitation probability. The vulnerability is not listed in the CISA KEV catalog. Attacks are client‑side and require user interaction with a malicious link or page. The lack of a widespread exploit indicates a lower risk, but the compromised context can be abused if the user is a privileged actor.
OpenCVE Enrichment