Impact
Adobe Experience Manager is vulnerable to a DOM‑based Cross‑Site Scripting flaw that can lead to arbitrary JavaScript execution in the victim’s browser context. An attacker could manipulate the web page’s Document Object Model to inject malicious script without the need for server‑side code changes. Based on the description, it is inferred that the attack vector involves manipulating the DOM environment of a crafted webpage, requiring the victim to intentionally visit that page. The impact is the ability of the attacker to steal session cookies, deface pages, or execute further attacks on the user’s behalf. The flaw is identified as CWE‑79 and requires the victim to intentionally visit a crafted page, making it a user‑interaction vulnerability with scope changes in the affected applications.
Affected Systems
Adobe Experience Manager 6.5, Adobe Experience Manager 6.5 LTS, and Adobe Experience Manager as a Cloud Service are affected. No specific patch versions are indicated, but all versions listed by Adobe fall under the scope of the vulnerability.
Risk and Exploitability
The CVSS score of 5.4 indicates a medium severity, reflecting the need for user interaction and the limited impact beyond the victim’s browser. EPSS is not available, so current exploitation probability cannot be quantified; the flaw is not listed in the CISA KEV catalog. Attackers would need to host or embed malicious content that targets the vulnerable DOM handling of Experience Manager. Because the exploit requires victim interaction, it is less likely to spread automatically but still poses a risk where users are susceptible to phishing or malicious links.
OpenCVE Enrichment