Impact
Adobe Experience Manager is vulnerable to a DOM‑based Cross‑Site Scripting flaw that allows an attacker to inject malicious JavaScript into a page viewed by a victim. The exploit requires the victim to visit a specially crafted webpage, after which code runs in the context of that site, potentially enabling theft of session cookies, login credentials, or defacement. The flaw is a client‑side input handling weakness classified as CWE‑79.
Affected Systems
The affected products are Adobe Experience Manager versions 6.5, the 6.5 LTS release, and the hosted cloud variant of Experience Manager. No specific subcomponents were enumerated; the vulnerability applies to the general page rendering mechanism across these releases.
Risk and Exploitability
The CVSS score of 5.4 indicates a moderate risk, and the vulnerability is not listed in the CISA KEV catalog. Because exploitation requires user interaction, the attack vector is likely an engineered social‑engineering or phishing link that directs a user to a malicious Adobe Experience Manager page. Without immediate patching, the moderate severity offers a reasonable window for an attacker to deliver malicious script, especially in high‑traffic or public sites.
OpenCVE Enrichment