Impact
Adobe Experience Manager is vulnerable to a DOM‑based Cross‑Site Scripting flaw. The flaw allows an attacker to inject malicious JavaScript into the page’s Document Object Model, causing the script to run with the full privileges of the victim’s browser session. The vulnerability changes the scope, meaning that if an attacker can persuade a user to visit a crafted URL, the affected component can be compromised, potentially leading to session hijacking or further exploitation within the same web application.
Affected Systems
The flaw affects Adobe Experience Manager versions 6.5, 6.5 LTS, and the cloud‑service offering, all of which may be deployed in on‑premise or cloud environments.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate severity. The EPSS value is not available and the issue is not listed in CISA’s KEV catalog, suggesting a lower likelihood of widespread exploitation. However, since the flaw requires user interaction—namely, visiting a specially crafted page—an attacker can influence consumers with targeted phishing or social engineering campaigns. Legacy or custom components that process unsafe input could expand the impact, so the risk is considered moderate but non‑negligible.
OpenCVE Enrichment