Impact
The vulnerability is a DOM‑based Cross‑Site Scripting flaw in Adobe Experience Manager. Attackers can craft a webpage containing malicious JavaScript that, when a victim visits it, is executed by the victim’s browser in the context of the affected site. The flaw allows arbitrary script execution in the user’s browser session and can be used to steal credentials, hijack sessions, or deface content. The weakness is classified as CWE‑79.
Affected Systems
Adobe Experience Manager 6.5, the 6.5 LTS release, and the cloud‑based edition of Adobe Experience Manager are impacted. The specific affected versions are the default releases of these products, as listed by Adobe. System administrators should verify whether their installations correspond to these releases.
Risk and Exploitability
The CVSS score is 5.4, indicating moderate severity. The EPSS score is not available, so the exploitation likelihood remains uncertain, but the vulnerability requires end‑user interaction with a crafted page. It is not listed in CISA’s KEV catalog, suggesting no known active exploitation. Attackers would need to lure a user to visit a malicious URL; once the page loads, the script runs in the browser, potentially exposing sensitive data or user accounts.
OpenCVE Enrichment