Impact
This vulnerability allows an attacker to insert malicious JavaScript into a victim’s browser by manipulating the document object model. The flaw is triggered when a user visits a crafted web page and the attacker can execute code under the victim’s security context. This can lead to theft of session cookies, defacement, or other client‑side attacks, but does not provide direct access to the server or data beyond what a compromised browser can access.
Affected Systems
Adobe Experience Manager 6.5, Adobe Experience Manager 6.5 LTS, and Adobe Experience Manager as a Cloud Service are affected. Version details are not explicitly listed in the advisory, but the impacted releases are those identified by Adobe as having this DOM‑based XSS flaw.
Risk and Exploitability
The CVSS v3 score is 5.4, indicating a moderate impact. EPSS data is not available, and the vulnerability is not listed in CISA’s KEV catalog. Exploitation requires user interaction; an attacker must convince a victim to visit a maliciously crafted URL. The affected scope is changed, meaning the vulnerability might affect the application's operational context rather than separate user accounts. Given the moderate CVSS score and lack of widespread exploitation data, the risk is moderate but end‑users could still be impacted through phishing or malicious hyperlinks.
OpenCVE Enrichment