Impact
Adobe Experience Manager contains a DOM‑based cross‑site scripting flaw that lets an attacker inject and run malicious JavaScript in a victim’s browser session when the victim visits a carefully crafted URL or webpage. The vulnerability depends on the victim’s browser environment and does not allow arbitrary code execution on the server, but it can compromise user credentials, session data, or perform actions on behalf of the user. The flaw is identified as CWE‑79 and the description notes a change in scope, indicating that the impact may extend beyond the original user context.
Affected Systems
The affected products are Adobe Experience Manager 6.5, the 6.5 LTS release, and the cloud‑based Adobe Experience Manager as a Cloud Service. No additional version details are supplied, so all instances of these products are potentially vulnerable.
Risk and Exploitability
The CVSS score of 5.4 represents a moderate level of risk. The EPSS score is not available, which limits precise exploitation probability data, and the issue is not listed in CISA's KEV catalog. Because exploitation requires a victim to click or otherwise interact with a malicious page, the attack vector is user‑initiated. While the CVSS indicates moderate risk, the lack of publicly known exploits or KEV listing suggests the likelihood of widespread exploitation is currently low. Nonetheless, organizations should treat the vulnerability as a valid threat to user sessions and data integrity.
OpenCVE Enrichment