Impact
Adobe Experience Manager is vulnerable to a DOM‑based cross‑site scripting flaw that allows an attacker to inject and execute JavaScript within the context of a victim’s browser. The flaw is triggered by manipulating the Document Object Model (DOM) environment via a crafted URL or payload. Because the effect only impacts client‑side code, the scope is limited to the victim’s session, but the injected script can perform malicious actions such as stealing credentials, hijacking sessions, or defacing the page. The weakness is classified as CWE‑79.
Affected Systems
Affected products include Adobe Experience Manager 6.5, Adobe Experience Manager 6.5 LTS, and Adobe Experience Manager as a Cloud Service. All three releases are impacted; users should verify the exact build and apply the vendor‑issued fix accordingly.
Risk and Exploitability
The CVSS score of 5.4 indicates a moderate risk level. No EPSS data is available and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires the target user to visit a malicious webpage or link, meaning user interaction is a prerequisite. Once the victim’s browser processes the crafted input, the attacker’s injected script runs with the privileges of the browser context, potentially compromising data confidentiality and integrity for that session.
OpenCVE Enrichment