Impact
Adobe Experience Manager is vulnerable to a DOM‑based Cross‑Site Scripting flaw that allows an attacker to run malicious JavaScript in the context of a victim’s browser. The flaw requires the victim to visit a crafted webpage and, when satisfied, the attacker can alter or access DOM elements to inject code. The vulnerability changes the scope of the affected environment, increasing the potential for abuse within the user’s session.
Affected Systems
The flaw affects Adobe Experience Manager 6.5, the 6.5 LTS maintenance stream, and the AEM as a Cloud Service deployment option. All installations that have not applied the vendor's fix for this issue are potentially vulnerable.
Risk and Exploitability
With a CVSS score of 5.4 the risk is moderate; no EPSS score is published and the vulnerability is not listed in CISA’s KEV catalog. Exploitation requires user interaction and would only succeed when a victim navigates to a maliciously crafted page. As an attacker would execute code in the victim’s browser context, the principal impact is client‑side compromise such as cookie theft or session hijacking, but the ability to affect the server is limited by the scope change indicated in the advisory.
OpenCVE Enrichment