Impact
This vulnerability is a DOM-based Cross‑Site Scripting flaw that allows an attacker to inject and execute malicious JavaScript within the victim’s browser context. The flaw requires the victim to visit a crafted web page, after which the attacker can hijack the session, steal data or perform other malicious actions. Because the attacker only needs a victim’s interaction, the damage is limited to that user’s session unless additional exploitation techniques are combined.
Affected Systems
Adobe Experience Manager versions 6.5, the long‑term support 6.5 LTS, and the Experience Manager as a Cloud Service are affected. No specific minor version changes are listed, so any deployment of these product lines with the described code paths is considered vulnerable.
Risk and Exploitability
The CVSS base score of 5.4 classifies this as a moderate‑severity issue. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog, indicating no known widespread exploitation. The likely attack vector is a user‑initiated visit to a maliciously crafted URL that manipulates the DOM. Successful exploitation requires the victim’s interaction and can enable the attacker to run arbitrary JavaScript in the victim’s browser context, potentially compromising confidentiality and integrity of the session
OpenCVE Enrichment