CRITICAL🇵🇱 Wersja polska

CVE-2025-64539

CVSS 9.3v3.1pub. 2025-12-10upd. 2025-12-12

Adobe Experience Manager versions 6.5.23 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could lead to arbitrary code execution. An attacker could exploit this vulnerability by injecting malicious scripts into a web page that are executed in the context of the victim's browser. A successful attacker can abuse this to achieve session takeover, increasing the confidentiality and integrity impact as high. Exploitation of this issue requires user interaction in that a victim must visit a crafted malicious page.

🤖 AI Analysis
How it works

An attacker injects a malicious script into a web page, which is then executed in the context of the victim's browser (DOM-based XSS). The vulnerability mechanism relies on improper handling of input data on the client side — the script modifies the document object model (DOM) without proper sanitization. The attack requires user interaction: the victim must visit a specially crafted malicious page. After successful payload execution, the attacker can take over the user's active session.

Impact

Successful exploitation of the vulnerability allows an attacker to take over the session of a logged-in user (session takeover) and execute arbitrary code in the context of their browser, resulting in high risk to data confidentiality and integrity.

Mitigation & patch

Apply patches available from the manufacturer according to the references — detailed information about patched versions is available in Adobe's security bulletin: https://helpx.adobe.com/security/products/experience-manager/apsb25-115.html

Who is affected

Adobe Experience Manager in versions 6.5.23 and earlier.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
  • Adobe Experience Manager

    APP
    Adobe
    6.5< 6.5.24.0< 2025.12.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCEXSS
CWE
References

Related vulnerabilities

CVE-2026-48359CRITICAL9.6PL ✓same product

Adobe Experience Manager — XXE umożliwiające RCE i odczyt plików

CVE-2026-48259CRITICAL9.6PL ✓same product

Adobe Experience Manager — SSRF umożliwiający zdalne wykonanie kodu

CVE-2026-34691CRITICAL9.3PL ✓same product

Stored XSS w Adobe Experience Manager Forms JEE – krytyczna podatność

CVE-2025-64537CRITICAL9.3PL ✓same product

DOM-based XSS w Adobe Experience Manager umożliwiający RCE

CVE-2025-64538CRITICAL9.3PL ✓same product

DOM-based XSS w Adobe Experience Manager — możliwe RCE i przejęcie sesji