Impact
The vulnerability is a DOM-based cross-site scripting flaw that allows an attacker to inject malicious JavaScript into a victim’s browser by manipulating the DOM environment. An attacker can trigger this flaw by crafting a malicious URL or page that the victim must visit, after which the script executes with the privileges of the victim’s session. The primary impact is the ability to run arbitrary client-side code, potentially leading to session hijacking, data theft, or defacement of the web application.
Affected Systems
Adobe Experience Manager 6.5, 6.5 LTS, and the Cloud Service are impacted. These versions lack the fix for the DOM-based XSS that has been reported, and the flaw resides in the web content rendering component.
Risk and Exploitability
The CVSS score of 5.4 indicates a medium severity, while the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires user interaction, limiting the likelihood of automated attacks. The scope change suggests that the flaw could potentially affect other components if an attacker escalates beyond the initial page, increasing the overall risk. Prompt remediation is advised because arbitrary client-side code execution can compromise user data and application integrity.
OpenCVE Enrichment