Impact
Adobe Experience Manager is susceptible to a DOM‑based Cross‑Site Scripting flaw that allows an attacker to inject and run arbitrary JavaScript in the victim’s browser. The vulnerability requires that the victim visits a specially crafted web page, at which point the attacker’s script can execute within the browser context. Because the attack operates in the client environment, it cannot alter server‑side data but can execute any code that the browser permits.
Affected Systems
The affected products are Adobe Experience Manager 6.5, the 6.5 LTS release, and the Adobe Experience Manager as a Cloud Service offering. No particular sub‑versions are identified in the CNA data, so all current releases within these lines should be considered vulnerable until a vendor‑supplied fix is applied.
Risk and Exploitability
The CVSS score of 5.4 indicates a moderate severity, but the EPSS score of less than 1% suggests a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Attackers must entice a user to visit a malicious URL, making user interaction a prerequisite; thus the risk to an organization depends largely on how widely exposed the affected AEM instances are and how likely users are to click a crafted link. The scope change flag indicates that the vulnerability may affect a broader set of resources than originally anticipated.
OpenCVE Enrichment