Impact
Adobe Experience Manager is vulnerable to a DOM-based Cross‑Site Scripting flaw that allows an attacker to inject and execute malicious JavaScript inside the victim’s browser. The flaw requires the victim to visit a crafted web page, after which the browser’s DOM environment is manipulated to run the attacker’s payload. Because the code runs with the victim’s privileges, an attacker could log in as the user, hijack the session, exfiltrate personal data, or deface site content, all without affecting the server itself.
Affected Systems
Vulnerable versions include Adobe Experience Manager 6.5, Adobe Experience Manager 6.5 LTS, and the Adobe Experience Manager as a Cloud Service platform. Specific patch details are provided in Adobe’s Security Bulletin APSB26‑98; no version exclusions are listed in the available data.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate severity. EPSS data is unavailable, so exploitation probability is unknown, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a malicious link or embedded content that a user opens, which is inferred from the requirement for user interaction. Exploitation is client‑side only and would not affect other users unless a compromised site is widely shared. Given the moderate score and lack of widespread exploitation evidence, the risk is moderate but warrants timely mitigation.
OpenCVE Enrichment