Adobe Experience Manager versions 6.5.23 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could lead to arbitrary code execution. An attacker could exploit this vulnerability by injecting malicious scripts into a web page that are executed in the context of the victim's browser. A successful attacker can abuse this to achieve session takeover, increasing the confidentiality and integrity impact as high. Exploitation of this issue requires user interaction in that a victim must visit a crafted malicious page.
An attacker injects a malicious script into a web page, which is then executed in the context of the visitor's browser. The vulnerability is DOM-based in nature, meaning that the malicious payload is processed on the client side by the browser's DOM mechanisms, without requiring persistent storage on the server side. Exploitation requires user interaction — the victim must visit a specially crafted malicious website.
A successful attack allows for session takeover of a logged-in user and execution of arbitrary JavaScript code in their browser, resulting in a high level of breach of confidentiality and integrity of data accessible within the session context.
Apply patches available from the vendor according to the references: https://helpx.adobe.com/security/products/experience-manager/apsb25-115.html
Adobe Experience Manager in version 6.5.23 and earlier.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:NAdobe Experience Manager
APPAdobe6.5< 6.5.24.0< 2025.12.0
Related vulnerabilities
Adobe Experience Manager — XXE umożliwiające RCE i odczyt plików
Adobe Experience Manager — SSRF umożliwiający zdalne wykonanie kodu
Stored XSS w Adobe Experience Manager Forms JEE – krytyczna podatność
DOM-based XSS w Adobe Experience Manager — możliwe RCE i przejęcie sesji
DOM-based XSS w Adobe Experience Manager umożliwiający RCE