Impact
Adobe Experience Manager is affected by a DOM-based Cross‑Site Scripting (XSS) vulnerability identified as CWE‑79. An attacker can manipulate the DOM environment to inject and execute malicious JavaScript in the victim’s browser. The exploit requires user interaction: a victim must visit a specially crafted web page. Successful exploitation could allow the attacker to run arbitrary scripts in the context of the victim, potentially leading to session hijacking, credential theft or defacement.
Affected Systems
Vendors: Adobe. Products: Adobe Experience Manager 6.5, Adobe Experience Manager 6.5 LTS, and Adobe Experience Manager as a Cloud Service. The CVE references do not provide granular version ranges beyond the 6.5 family; therefore, any installation of these products that has not yet applied an official patch is considered vulnerable.
Risk and Exploitability
The vulnerability has a CVSS score of 5.4, placing it in the medium severity range, and it is currently not listed in the CISA Known Exploited Vulnerabilities catalog. Because exploitability depends on the victim deliberately accessing a malicious page, the risk is moderated, though any compromised user session poses a risk to the hosted content. The EPSS score is not available, indicating the current probability estimates are unavailable, but the scope change suggests privileges could be escalated within the browser context after exploitation. Until a patch is applied, the best defenders should assume the risk exists and mitigate accordingly.
OpenCVE Enrichment