Impact
Adobe Experience Manager is impacted by a DOM-based cross‑site scripting vulnerability that allows an attacker to execute malicious JavaScript inside the victim’s browser context. The flaw requires the victim to visit a specially crafted page and does not change privileges but does alter the integrity of the user session by injecting script that can exfiltrate data or perform actions on behalf of the user.
Affected Systems
The vulnerability compromises Adobe Experience Manager 6.5, Adobe Experience Manager 6.5 LTS, and the Adobe Experience Manager as a Cloud Service offering. No specific build numbers are listed, so all instances of these products are considered potentially affected.
Risk and Exploitability
The CVSS score of 5.4 indicates a medium severity assessment. The EPSS score is not reported, and the vulnerability is not included in the CISA KEV catalog, so current exploitation evidence is limited. Exploitation requires the victim to load a crafted URL, making the attack vector user interaction‑driven. Given the lack of a public exploit and the need for user action, the immediate risk is moderate, but the potential impact on session integrity and data exposure warrants prompt remediation.
OpenCVE Enrichment