Impact
Adobe Experience Manager is vulnerable to a DOM-based Cross‑Site Scripting flaw that allows an attacker to inject and execute arbitrary JavaScript in the victim's browser context. The flaw is triggered when a user visits a crafted webpage that manipulates the Document Object Model. Once executed the malicious script can hijack sessions, deface content, or redirect users to phishing sites. The issue is rated as scope changed, indicating that the vulnerability can potentially affect a broader set of resources within the affected application.
Affected Systems
The vulnerability affects the following Adobe Experience Manager releases: 6.5, 6.5 LTS, and the Cloud Service edition. No specific sub-version information is provided, so any deployment running these major releases may be impacted until the Adobe advisory is applied.
Risk and Exploitability
The CVSS score is 5.4, which falls in the medium severity range. The EPSS score is not available and it is not listed in the CISA KEV catalog, suggesting that no publicly known exploits have been reported yet. Exploitation requires user interaction – the victim must click a malicious link or open a manipulated page – and the vulnerability is limited to the victim's browser, so the potential damage is confined to the victim's session unless additional credentials or elevated privileges are compromised. Regular monitoring for suspicious scripts and applying the patch remain the recommended controls.
OpenCVE Enrichment