Impact
Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting flaw that allows an attacker to manipulate the DOM environment and execute malicious JavaScript in the victim’s browser when the user visits a crafted webpage. The attack requires user interaction and can run arbitrary code within the browser context, potentially compromising the user’s session or data.
Affected Systems
Adobe Experience Manager 6.5, Adobe Experience Manager 6.5 LTS, and Adobe Experience Manager as a Cloud Service are listed as affected. No specific patch versions are provided in the advisory, but all of the mentioned products are impacted.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate overall risk. The EPSS score is not available and the vulnerability is not in the CISA KEV catalog, suggesting limited evidence of active exploitation. Exploitation requires the victim to load a malicious URL, so a user-interaction attack model applies, and the impact is confined to the victim’s browser session.
OpenCVE Enrichment