Impact
Adobe Experience Manager is vulnerable to a DOM-based Cross‑Site Scripting flaw, identified as CWE‑79. An attacker can inject malicious JavaScript that runs in the victim’s browser context while the user simply visits a crafted page. Exploitation of this issue changes the scope, meaning it can affect the vulnerability’s impact on the user’s session or data, but it does not grant control of the underlying server system. Affected systems include Adobe Experience Manager 6.5, Adobe Experience Manager 6.5 LTS, and Adobe Experience Manager as a Cloud Service, all versions prior to any mitigation that addresses this DOM‑based XSS. The CVSS base score of 5.4 indicates a medium‑level severity, the EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a crafted URL or page that the victim must interact with; user awareness and click‑through of malicious content are prerequisites for exploitation.
Affected Systems
Adobe Experience Manager 6.5, Adobe Experience Manager 6.5 LTS, and Adobe Experience Manager as a Cloud Service.
Risk and Exploitability
The medium CVSS score signals a notable risk if users are tricked into visiting malicious content, but the lack of an EPSS rating suggests that known exploitation is currently low or not publicly confirmed. Because the issue requires user interaction, defenders can mitigate risk by restricting or monitoring content that can trigger DOM‑based scripting, while waiting for Adobe to release a patch or advisory.
OpenCVE Enrichment