Impact
Adobe Experience Manager is vulnerable to a DOM‑based Cross‑Site Scripting flaw that allows an attacker to execute malicious JavaScript in the victim's browser. The flaw arises when untrusted input is processed directly in the document object model, enabling manipulation of page content. An attacker can exploit this by delivering a specially crafted URL that a user must click on, causing the injected script to run with the privileges of the current user session.
Affected Systems
The affected products are Adobe Experience Manager 6.5, the 6.5 LTS release, and the cloud‑service variant. No other editions were listed as vulnerable. The flaw exists across all these releases and does not appear restricted by configuration.
Risk and Exploitability
The CVSS score is 5.4, indicating moderate severity. The exploit requires user interaction and a crafted link; no evidence of widespread exploitation is reported, and the vulnerability is not in CISA’s KEV catalog. The absence of an EPSS score means the exact likelihood is unknown, but user‑click required attacks can still pose a threat, especially in environments where users can visit arbitrary URLs.
OpenCVE Enrichment