Impact
Adobe Experience Manager is affected by a DOM‑based Cross‑Site Scripting vulnerability that enables an attacker to inject and execute malicious JavaScript in the victim’s browser. The flaw arises from improper sanitization of data used to manipulate the Document Object Model, allowing the injection of client‑side code. This is a classic input‑validation weakness identified as CWE‑79 and can compromise confidentiality, integrity, or availability of the user’s session if the malicious script performs phishing, credential theft, or further exploitation. The vulnerability is scoped to the user’s browser context and requires user interaction to trigger, meaning that simply hosting content does not automatically provide an attack surface.
Affected Systems
The affected products are Adobe Experience Manager 6.5, Adobe Experience Manager 6.5 LTS, and Adobe Experience Manager as a Cloud Service. No specific sub‑versions are listed, but all releases under the 6.5 umbrella are considered vulnerable until patched. The vulnerability is documented for the core product and the cloud‑based deployment model, so both on‑premises and SaaS customers must verify installation dates and update status.
Risk and Exploitability
The recorded CVSS score is 5.4, indicating moderate severity with a requirement for user interaction. EPSS data is not available, so the exploitation likelihood cannot be quantified, but the absence of a KEV listing suggests it is not a currently widely exploited issue. The attack vector is inferred to be web‑based, requiring a victim to download or open a crafted webpage that manipulates the DOM to load malicious JavaScript. The scope change in the description implies the impact is limited to the victim’s browser session, not system‑wide privileges.
OpenCVE Enrichment