Impact
The vulnerability is a DOM-based cross‑site scripting flaw that allows an attacker to embed arbitrary JavaScript into a victim’s browser session. By manipulating the Document Object Model environment in a visited page, an attacker can execute code that may compromise information confidentiality, data integrity, or session availability. The flaw aligns with CWE‑79, a flaw where untrusted input is inserted into the DOM without proper sanitization.
Affected Systems
Adobe Experience Manager 6.5, Adobe Experience Manager 6.5 LTS, and Adobe Experience Manager as a Cloud Service are affected by this flaw.
Risk and Exploitability
The assessed CVSS score is 5.4, indicating a moderate risk. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog. Exploitation requires the victim to visit a specially crafted webpage, leveraging the user's interaction to deliver the malicious script. The attack vector is therefore an in‑browser delivery via manipulated DOM, and the primary impact is execution of arbitrary JavaScript within the victim’s session, potentially leading to data theft or session hijacking.
OpenCVE Enrichment