Impact
Adobe Experience Manager has a DOM-based Cross-Site Scripting vulnerability. An attacker could inject and execute malicious JavaScript in the victim’s browser by manipulating the DOM. Exploitation requires the victim to visit a specially crafted webpage and causes a change in scope.
Affected Systems
Adobe Experience Manager 6.5, Adobe Experience Manager 6.5 LTS, and Adobe Experience Manager as a Cloud Service are susceptible.
Risk and Exploitability
The CVSS score is 5.4, indicating moderate risk. Exploitation requires user interaction, so phishing or a malicious link is the likely vector. EPSS data is not available, and the vulnerability is not listed in CISA KEV, so widespread exploitation has not been reported. The scope change warrants timely attention.
OpenCVE Enrichment