Impact
Adobe Experience Manager is vulnerable to a DOM‑based Cross‑Site Scripting flaw that is triggered when a victim visits a specially crafted URL. The attacker manipulates the browser’s document object model to inject and execute malicious JavaScript within the victim’s context, executing client‑side code execution. Successful exploitation does not require server‑side changes.
Affected Systems
Affected systems include Adobe Experience Manager version 6.5, the 6.5 LTS release, and the as‑a‑Cloud‑Service deployment. The vulnerability is present across these product lines but no specific patch or version numbers are listed beyond the general product identifiers.
Risk and Exploitability
The CVSS score of 5.4 places the flaw in the medium severity range. EPSS score is not available, and the issue is not currently listed in CISA’s KEV catalog. Exploitation requires user interaction: a victim must click a malicious link or visit a crafted page. The change in scope indicates a broader impact, but the exact components remain unspecified.
OpenCVE Enrichment