Impact
Adobe Experience Manager is affected by a DOM‑based Cross‑Site Scripting vulnerability that allows an attacker to execute malicious JavaScript within the victim's browser. The flaw exists when the DOM environment is manipulated through a crafted webpage. The vulnerability can be exploited only when a user interacts with the malicious page, and it has a changed scope, indicating that the affected code may gain broader access or affect additional components.
Affected Systems
The flaw affects Adobe Experience Manager 6.5, 6.5 LTS, and the Cloud Service offering. No specific patch version numbers are supplied in the CVE, so all installations of these products are potentially vulnerable until an official fix is applied.
Risk and Exploitability
The CVSS score of 5.4 places the vulnerability in the medium severity range. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting it is not known to be actively exploited in the wild. Because the flaw requires user interaction to trigger, the likelihood of exploitation is moderated, but the impact of a successful attack could include arbitrary code execution in the victim’s browser context.
OpenCVE Enrichment