Impact
Adobe Experience Manager is affected by a DOM‑based Cross‑Site Scripting flaw that lets an attacker craft malicious input, causing the browser to execute arbitrary JavaScript in the victim’s session. This vulnerability can compromise the confidentiality and integrity of user data and enable attackers to hijack sessions or exfiltrate information. Exploitation requires the victim to open a crafted page, so the attack vector is a browser‑based user interaction.
Affected Systems
The flaw impacts Adobe Experience Manager 6.5, including the 6.5 LTS release, and the Adobe Experience Manager as a Cloud Service offering. No additional version details are supplied.
Risk and Exploitability
The CVSS score is 5.4, indicating moderate severity. The EPSS score is unavailable and the vulnerability is not listed in the CISA KEV catalog, suggesting limited evidence of active exploitation. The flaw requires user interaction with a crafted webpage, making it a client‑side XSS. The changed scope in the CVSS vector implies that the vulnerability can affect confidentiality and integrity, but no evidence of privilege escalation is provided. Overall risk is moderate, and patching is recommended.
OpenCVE Enrichment