CRITICAL🇵🇱 Wersja polska

CVE-2025-64538

CVSS 9.3v3.1pub. 2025-12-10upd. 2025-12-12

Adobe Experience Manager versions 6.5.23 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could lead to arbitrary code execution. An attacker could exploit this vulnerability by injecting malicious scripts into a web page that are executed in the context of the victim's browser. A successful attacker can abuse this to achieve session takeover, increasing the confidentiality and integrity impact as high. Exploitation of this issue requires user interaction in that a victim must visit a crafted malicious page.

🤖 AI Analysis
How it works

An attacker injects a malicious script into a web page, which is then executed in the context of the victim's browser (DOM-based XSS). The vulnerability is triggered on the client side — the browser processes the malicious payload without the need for it to be reflected by the server. For the attack to succeed, the victim must visit a specially crafted malicious website. Successful exploitation allows the attacker to hijack the user's session (session takeover).

Impact

An attacker can hijack the session of a logged-in user (session takeover), gaining unauthorized access to their account and potentially executing arbitrary code in the context of the victim's browser. The impact on data confidentiality and integrity is assessed as high.

Mitigation & patch

Security patches available from the vendor should be applied in accordance with the references (Adobe Security Bulletin APSB25-115: https://helpx.adobe.com/security/products/experience-manager/apsb25-115.html).

Who is affected

Adobe Experience Manager in version 6.5.23 and all earlier versions.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
  • Adobe Experience Manager

    APP
    Adobe
    6.5< 6.5.24.0< 2025.12.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCEXSS
CWE
References

Related vulnerabilities

CVE-2026-48359CRITICAL9.6PL ✓same product

Adobe Experience Manager — XXE umożliwiające RCE i odczyt plików

CVE-2026-48259CRITICAL9.6PL ✓same product

Adobe Experience Manager — SSRF umożliwiający zdalne wykonanie kodu

CVE-2026-34691CRITICAL9.3PL ✓same product

Stored XSS w Adobe Experience Manager Forms JEE – krytyczna podatność

CVE-2025-64537CRITICAL9.3PL ✓same product

DOM-based XSS w Adobe Experience Manager umożliwiający RCE

CVE-2025-64539CRITICAL9.3PL ✓same product

DOM-based XSS w Adobe Experience Manager umożliwiający RCE