Impact
The flaw is a DOM‑based XSS that lets an attacker manipulate the browser’s Document Object Model and execute arbitrary JavaScript in the context of the victim’s session. The attacker must direct the target to a specially crafted URL or page served by Adobe Experience Manager, after which the embedded script runs with the privileges of the user, potentially exposing data or enabling further compromise.
Affected Systems
Adobe Experience Manager versions 6.5, 6.5 LTS, and the Cloud Service are impacted. No specific sub‑versions are listed, implying all builds from these product lines are vulnerable until an update is applied.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate severity, and the vulnerability can be triggered with only user interaction and no special privileges. EPSS data is unavailable, so the likelihood of exploitation is unclear, and the flaw is not yet listed in the CISA KEV catalog. Because the scope is changed, the attack can affect privileged paths within the application, raising the potential impact if a user is authenticated.
OpenCVE Enrichment