Impact
Adobe Experience Manager is vulnerable to a DOM-based Cross‑Site Scripting issue that enables an attacker to inject and run malicious JavaScript in a victim’s browser when the victim visits a specially crafted web page. The flaw allows manipulation of the Document Object Model to execute code within the context of the victim’s session, and it is marked as scope‑changed, meaning the impact is confined to the user’s browser environment rather than the server or other users.
Affected Systems
The vulnerability affects Adobe Experience Manager 6.5, Adobe Experience Manager 6.5 LTS, and Adobe Experience Manager as a Cloud Service. Any installation of these products that has not applied the vendor’s patch is potentially vulnerable.
Risk and Exploitability
The CVSS score of 5.4 indicates a moderate risk level. No EPSS data is available and the vulnerability is not listed in the CISA KEV catalog, suggesting limited exploitation activity. The likely attack vector is a web‑based social engineering scenario where a user must visit a malicious page that triggers the DOM manipulation. Successful exploitation would compromise the confidentiality and integrity of the victim’s browser session for that user only, without providing system‑wide control.
OpenCVE Enrichment