Impact
Adobe Experience Manager is vulnerable to a DOM‑based Cross‑Site Scripting flaw that allows an attacker to manipulate the browser’s Document Object Model and cause arbitrary JavaScript execution within the victim’s browser context. The flaw is triggered when a user visits a specially crafted web page, requiring user interaction and changing the vulnerability’s scope.
Affected Systems
Affected products are Adobe Experience Manager 6.5, Adobe Experience Manager 6.5 LTS, and Adobe Experience Manager as a Cloud Service. Every installation of these versions is potentially vulnerable until a vendor security update is applied. The advisory does not list a specific patched version, so all current releases should be considered at risk.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate severity. The EPSS score is not available, so no current exploitation probability has been published. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires the victim to load a crafted URL, making it a user‑interaction‑dependent attack. Given the moderate score and lack of a widely available exploit, the immediate risk is moderate, but the capability for arbitrary script execution mandates timely remediation.
OpenCVE Enrichment