Impact
Adobe Experience Manager is vulnerable to a DOM‑based Cross‑Site Scripting flaw that allows an attacker to inject and execute arbitrary JavaScript in the victim’s browser when the victim visits a malicious webpage. The vulnerability is exploited by manipulating the page’s Document Object Model; no local privileges are required and the attackers need only entice a user to click a crafted link. Once executed, the attacker can steal session cookies, read or modify page content, and perform actions on behalf of the user. The CVSS rating of 5.4 indicates a moderate risk to confidentiality, integrity and availability, with the primary impact being client‑side compromise rather than server compromise.
Affected Systems
Adobe Experience Manager 6.5, Adobe Experience Manager 6.5 LTS and Adobe Experience Manager as a Cloud Service are affected. The vulnerability remains in all supported releases of these products.
Risk and Exploitability
The exploit requires user interaction, so broader penetration depends on social engineering or delivery via phishing. The EPSS score is not available, and the vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities catalog, suggesting no mass‑mode exploitation has been observed. However, the CVSS score of 5.4 and the requirement for a victim‑to‑visit a crafted page imply a realistic risk for targeted attacks, especially in environments where users frequently open emails or visit external sites.
OpenCVE Enrichment