Impact
Adobe Experience Manager is vulnerable to a DOM‑based Cross‑Site Scripting flaw that allows an attacker to inject and execute malicious JavaScript within a victim’s browser context. The flaw occurs when the application processes crafted input that alters the DOM environment, leading to unintended script execution. This vulnerability can compromise confidentiality, integrity, and availability of information handled by the victim’s session, and the wrongdoing is scoped to the user’s browser session, not system‑wide. "Scope is changed" indicates the vulnerability can affect more than just the local context, but still requires the user to interact with the crafted content.
Affected Systems
Affected products include Adobe Experience Manager 6.5, Adobe Experience Manager 6.5 LTS, and Adobe Experience Manager as a Cloud Service. No specific versions are listed beyond these product lines; users of these releases should verify their exact build against Adobe’s advisory.
Risk and Exploitability
The CVSS score of 5.4 indicates a moderate severity for an XSS flaw. The EPSS score is not available, so the current exploitation probability is unknown, and the vulnerability is not included in the CISA KEV catalog. Exploitation requires victim interaction – a user must load a specially crafted web page. The attack vector is therefore indirect and depends on user click, but once triggered, the attacker can execute arbitrary JavaScript in the victim’s browser context. Given the absence of a publicly available exploit and the need for user interaction, the risk is moderate but remains non‑negligible for exposed applications.
OpenCVE Enrichment