Impact
Adobe Experience Manager is vulnerable to a DOM‑based Cross‑Site Scripting flaw. The issue allows an attacker who can craft a URL or webpage to inject and execute malicious JavaScript in the victim’s browser. Successful exploitation can lead to session hijacking, credential theft, or the execution of arbitrary code within the browser context. The vulnerability is identified as CWE‑79 and is noted to have a changed scope, indicating that the flaw may affect a broader set of operations than originally anticipated, though it still requires user interaction to trigger.
Affected Systems
The affected products are Adobe Experience Manager versions 6.5, 6.5 LTS, and the Adobe Experience Manager as a Cloud Service offering. These are the only products listed by the CNA as vulnerable. No additional version ranges are specified, so all current releases of these products are considered at risk until the vendor releases a patch.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate severity. The vulnerability requires that a victim load a maliciously crafted page, so it is not remotely exploitable without user interaction. The EPSS score is not available, and the issue is not listed in CISA’s KEV catalog, suggesting that no widespread active exploitation has been reported. Nonetheless, the potential for social‑engineering attacks and the scope change mean that organizations should treat this flaw as a significant risk and apply the update promptly.
OpenCVE Enrichment