Impact
Adobe Experience Manager is vulnerable to a DOM‑based Cross‑Site Scripting flaw, classified as CWE‑79. The flaw permits an attacker to supply crafted input that, when processed by the victim’s browser, causes malicious JavaScript to execute in the context of the user’s session. Exploitation requires that a victim visit a specially constructed page, but no authentication is needed and the attack can alter the scope of the victim’s session.
Affected Systems
Adobe Experience Manager 6.5, Adobe Experience Manager 6.5 LTS, and Adobe Experience Manager as a Cloud Service are all affected by this vulnerability.
Risk and Exploitability
The CVSS score of 5.4 indicates a medium impact: the flaw provides client‑side code execution without authentication but depends on user interaction. The absence of an EPSS rating and the fact that the vulnerability is not listed in CISA’s KEV catalog suggest limited exploitation traffic to date. However, because the flaw can be triggered from any web‑browsable link, an attacker could entice users to visit a malicious URL and thereby run arbitrary code in their browser context.
OpenCVE Enrichment