Impact
The vulnerability is a DOM-based Cross‑Site Scripting flaw (CWE‑79) in Adobe Experience Manager that allows an attacker to inject and execute malicious JavaScript in a victim’s browser by visiting a crafted webpage. Based on the description, it is inferred that the attacker could potentially steal session data, manipulate the page DOM, or perform phishing attacks. The flaw requires user interaction with the crafted URL and does not permit server‑side code execution; however, because the scope is changed it may affect additional components indirectly when the victim proceeds to further content.
Affected Systems
The affected products are Adobe Experience Manager 6.5, Adobe Experience Manager 6.5 LTS, and Adobe Experience Manager as a Cloud Service. All versions within these product lines are vulnerable; no specific patch version is listed in the current advisory, so any deployment of those products should be considered at risk until a corrective update is applied.
Risk and Exploitability
The CVSS base score is 5.4, which classifies the vulnerability as moderate. The EPSS metric is not available, and the vulnerability is not listed in CISA’s KEV catalog, indicating no widely known public exploitation yet. The exploit requires an end‑user to click a malicious link, so the risk is primarily around phishing or social engineering attempts. Attackers would need only to send a crafted URL to users of the affected Adobe Experience Manager installations. As the issue triggers after user interaction, organizations should monitor for unusual user activity and enforce mitigations until a vendor fix is deployed.
OpenCVE Enrichment