Impact
Adobe Experience Manager is vulnerable to a DOM‑based Cross‑Site Scripting attack that allows an attacker to execute arbitrary JavaScript in the victim’s browser by manipulating the Document Object Model. The flaw can result in the theft of session data, defacement of the web page, or other malicious actions performed in the victim’s context. The vulnerability is a typical client‑side XSS (CWE‑79) that requires no privileged access on the server side.
Affected Systems
Affected installations include Adobe Experience Manager 6.5, the 6.5 LTS release, and the Cloud Service edition. Any environment running these versions that renders untrusted input into the DOM is potentially vulnerable. The vendors specified are Adobe, distributed as the Experience Manager product suite.
Risk and Exploitability
The CVSS score of 5.4 indicates a moderate severity for a client‑side vulnerability. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog. Attack requires user interaction; the victim must open a crafted webpage that triggers the DOM manipulation. Because the scope is changed, exploitation could affect higher privileges than the original context, increasing the potential impact. Overall risk is moderate and depends on user usage patterns and exposure to malicious URLs.
OpenCVE Enrichment