Impact
The vulnerability in Adobe Experience Manager is a DOM‑based Cross‑Site Scripting flaw that allows an attacker to manipulate the Document Object Model of a victim’s browser, executing arbitrary JavaScript within the context of the site. This exploitation requires the victim to visit a crafted webpage, after which malicious code runs client‑side and can steal credentials, perform actions on behalf of the user, or redirect to phishing sites. Because the flaw affects only the client environment, it does not compromise the server or other users, yet it can have significant impact on the affected individual's session. The CVSS scoring reflects a scope change, elevating the impact beyond a local context.
Affected Systems
Affected systems are Adobe Experience Manager 6.5, the 6.5 LTS release, and the Adobe Experience Manager as a Cloud Service platform. All builds prior to the latest patch contain the vulnerable DOM handling logic that processes user‑controlled input without proper sanitization.
Risk and Exploitability
The CVSS score of 5.4 indicates medium risk, and the EPSS score is not available, so the probability of exploitation in the wild is uncertain. The CVE is not listed in CISA KEV, suggesting no known active exploitation campaigns. Attackers would likely rely on social engineering or phishing to lure users to a malicious link, exploiting the user interaction requirement. Because the flaw is client‑side, defenders can mitigate by applying the vendor patch, sanitizing input, or blocking malicious script injection.
OpenCVE Enrichment