Impact
Adobe Experience Manager is affected by a DOM‑based Cross‑Site Scripting vulnerability that permits the execution of arbitrary JavaScript in a victim’s browser by manipulating the DOM through a crafted webpage. The flaw requires the victim to load a malicious page and does not need elevated privileges beyond the normal user context. It is identified as CWE‑79 and the advisory notes that scope has been changed, suggesting the impact may extend beyond a single component.
Affected Systems
Adobe Experience Manager 6.5, its LTS release, and the as‑a‑cloud deployment. No specific version numbers are listed, so the risk applies to all releases of these products until a patch is applied.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate severity. EPSS data is unavailable and the vulnerability is not listed in the CISA KEV catalog. Because exploitation requires the victim to open a crafted webpage, the attack vector is web‑based user interaction. The scope change implies that the vulnerability could affect a broader portion of the application, but it remains dependent on user interaction, which limits uncontrolled exploitation.
OpenCVE Enrichment