Impact
A DOM-based Cross‑Site Scripting vulnerability allows an attacker to manipulate the Document Object Model of a user’s browser and execute malicious JavaScript in the context of the victim. The flaw can be triggered by a crafted page that a user must load, after which the attacker can inject scripts that may read or alter page content, manipulate cookies, or hijack user sessions. The vulnerability is categorized as CWE‑79 and is reported with a CVSS score of 5.4, indicating a moderate severity effect when exploited.
Affected Systems
Adobe Experience Manager 6.5, its 6.5 LTS release, and the cloud‑based Experience Manager service are all affected. No specific version sub‑ranges are listed, so any installation of the mentioned products could be vulnerable until a patch is applied.
Risk and Exploitability
The CVSS base score of 5.4 places this issue in the medium risk range. Because exploitation requires user interaction and a crafted page, the EPSS score is not reported but the lack of a KEV listing suggests no widespread active exploitation has been observed yet. The likely attack vector is embedding a malicious link in emails or online posts that leads a user to visit a crafted page. Once the victim loads the page, the attacker’s injected script runs with the same privileges as the authenticated Experience Manager user, potentially exposing sensitive content or compromising user accounts.
OpenCVE Enrichment