Impact
Adobe Experience Manager is affected by a DOM-based Cross‑Site Scripting vulnerability. An attacker can manipulate the DOM environment to execute malicious JavaScript within the victim's browser. This requires the user to visit a crafted web page, meaning exploitation depends on user interaction. The flaw can alter the content served to the victim, allowing phishing, credential theft, or other client‑side attacks.
Affected Systems
Vulnerable versions include Adobe Experience Manager 6.5, Adobe Experience Manager 6.5 LTS, and Adobe Experience Manager as a Cloud Service. The documentation does not specify precise patch levels, so any release listed by Adobe as susceptible should be treated as affected until an official fix is applied.
Risk and Exploitability
The CVSS base score of 5.4 indicates moderate severity, while the EPSS score is unavailable. The vulnerability is not listed in the CISA KEV catalog. Because exploitation requires user interaction and there is no publicly known exploit, the likelihood of attack is moderate. The attacker’s potential impact is confined to the victim’s browser session, but may still enable credential compromise and phishing. The absence of a commercial exploit reduces immediate risk, yet the DOM‑based XSS nature and the need for social engineering still warrant timely remediation.
OpenCVE Enrichment