Impact
Adobe Experience Manager is affected by a DOM-based Cross‑Site Scripting vulnerability that allows an attacker to manipulate the Document Object Model of a victim’s browser and run arbitrary JavaScript. This can be used to steal session tokens, deface content, or perform other client‑side attacks. The flaw is triggered when a victim visits a specially crafted page, and it affects the scope of the application because the injected script can escape the original context.
Affected Systems
The vulnerability applies to Adobe Experience Manager 6.5, the 6.5 Long‑Term Support release, and the Adobe Experience Manager as a Cloud Service offering. The CVE entry does not list more granular patch versions, but the official advisory confirms that all current releases of these products are susceptible.
Risk and Exploitability
The CVSS score for this issue is 5.4, indicating moderate severity. No EPSS score is available, so the current exploitation probability is unknown, and the vulnerability is not present in the CISA KEV list. Exploitation requires user interaction—a victim must visit a malicious URL—making direct attacks dependent on social engineering or phishing. Given the scope change, the impact could extend beyond the original context if an attacker succeeds. Organizations should consider the vulnerability serious enough to warrant timely remediation.
OpenCVE Enrichment