Impact
Adobe Experience Manager is affected by a DOM-based Cross‑Site Scripting vulnerability that allows an attacker to manipulate the DOM environment and execute malicious JavaScript within the victim's browser context. The flaw requires that the victim visit a crafted webpage, after which injected script can run in the user's session. Successful exploitation could lead to session hijacking, credential theft, defacement, or unauthorized data access. The vulnerability is identified as CWE‑79 and the scope of the attack is changed, meaning that the impact remains within the victim's browser rather than impacting server‑side resources.
Affected Systems
Affected products are Adobe Experience Manager 6.5, the 6.5 LTS release, and Adobe Experience Manager as a Cloud Service. No further version granularity is provided, so any installation of these editions should be considered vulnerable.
Risk and Exploitability
The CVSS score of 5.4 indicates medium severity. EPSS information is not available, and the vulnerability is not listed in CISA's KEV catalog, suggesting limited exploitation data. Because exploitation requires user interaction with a crafted webpage, the risk is typically confined to social‑engineering attacks. Nevertheless, organizations with exposed Experience Manager instances should treat it as a moderate threat until the patch is applied.
OpenCVE Enrichment