Adobe Experience Manager versions 6.5.23 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could lead to arbitrary code execution. An attacker could exploit this vulnerability by injecting malicious scripts into a web page that are executed in the context of the victim's browser. A successful attacker can abuse this to achieve session takeover, increasing the confidentiality and integrity impact as high. Exploitation of this issue requires user interaction in that a victim must visit a crafted malicious page.
An attacker injects a malicious script into a web page, which is then executed in the context of the victim's browser (DOM-based XSS). The vulnerability is triggered on the client side — the browser processes the malicious payload without the need for it to be reflected by the server. For the attack to succeed, the victim must visit a specially crafted malicious website. Successful exploitation allows the attacker to hijack the user's session (session takeover).
An attacker can hijack the session of a logged-in user (session takeover), gaining unauthorized access to their account and potentially executing arbitrary code in the context of the victim's browser. The impact on data confidentiality and integrity is assessed as high.
Security patches available from the vendor should be applied in accordance with the references (Adobe Security Bulletin APSB25-115: https://helpx.adobe.com/security/products/experience-manager/apsb25-115.html).
Adobe Experience Manager in version 6.5.23 and all earlier versions.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:NAdobe Experience Manager
APPAdobe6.5< 6.5.24.0< 2025.12.0
Related vulnerabilities
Adobe Experience Manager — XXE umożliwiające RCE i odczyt plików
Adobe Experience Manager — SSRF umożliwiający zdalne wykonanie kodu
Stored XSS w Adobe Experience Manager Forms JEE – krytyczna podatność
DOM-based XSS w Adobe Experience Manager umożliwiający RCE
DOM-based XSS w Adobe Experience Manager umożliwiający RCE