Impact
A DOM‑based Cross‑Site Scripting flaw allows an attacker to inject and run malicious JavaScript in the victim’s browser. By manipulating the Document Object Model on a crafted page, the attacker can steal cookies, hijack sessions, or redirect the user to phishing sites. Although the vulnerability only affects client‑side code, the execution of arbitrary script can compromise the confidentiality and integrity of user data within the web application.
Affected Systems
Adobe Experience Manager products including version 6.5, the 6.5 LTS release, and the Cloud Service are affected. No specific version range was provided in the advisory, so all deployments of these products are potentially vulnerable until a patch is applied.
Risk and Exploitability
The CVSS score is 5.4, indicating a medium severity. Exploitation requires the user to visit a maliciously crafted page, so the attacker must first convince the victim to interact with the site. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting that no widespread weaponized exploitation has been reported. The scope change noted in the description indicates that the flaw may affect broader application components than initially expected, but the primary risk remains client‑side script execution.
OpenCVE Enrichment