Impact
Adobe Experience Manager is vulnerable to a DOM‑based Cross‑Site Scripting flaw that allows an attacker to execute malicious JavaScript within a victim’s browser. The flaw arises when a crafted URL or page modifies the Document Object Model to inject code that runs with the same origin as the site. An attacker needs the victim to visit a malicious link or page, after which the XSS payload can exfiltrate session data, redirect the user, or perform other browser‑based attacks. The CVSS score of 5.4 indicates a moderate risk that primarily affects confidentiality and integrity of authenticated user sessions without affecting system availability.
Affected Systems
Products affected are Adobe Experience Manager 6.5, Adobe Experience Manager 6.5 LTS, and Adobe Experience Manager as a Cloud Service. No specific patch version is listed in the current advisory; administrators should refer to the vendor guidance for the latest update that addresses this issue.
Risk and Exploitability
The risk is moderate with a CVSS score of 5.4 and no EPSS score provided. The vulnerability is not listed in the CISA KEV catalog, indicating no known active exploits. Exploitation requires the victim to interact with a crafted page, making it a user‑interaction‑dependent XSS. The scope change suggests that the flaw can affect more than the originating resource, potentially enabling privilege or domain escalation within the web application if not mitigated.
OpenCVE Enrichment