Adobe Experience Manager versions 6.5.23 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could lead to arbitrary code execution. An attacker could exploit this vulnerability by injecting malicious scripts into a web page that are executed in the context of the victim's browser. A successful attacker can abuse this to achieve session takeover, increasing the confidentiality and integrity impact as high. Exploitation of this issue requires user interaction in that a victim must visit a crafted malicious page.
An attacker injects a malicious script into a web page, which is then executed in the context of the victim's browser (DOM-based XSS). The vulnerability mechanism relies on improper handling of input data on the client side — the script modifies the document object model (DOM) without proper sanitization. The attack requires user interaction: the victim must visit a specially crafted malicious page. After successful payload execution, the attacker can take over the user's active session.
Successful exploitation of the vulnerability allows an attacker to take over the session of a logged-in user (session takeover) and execute arbitrary code in the context of their browser, resulting in high risk to data confidentiality and integrity.
Apply patches available from the manufacturer according to the references — detailed information about patched versions is available in Adobe's security bulletin: https://helpx.adobe.com/security/products/experience-manager/apsb25-115.html
Adobe Experience Manager in versions 6.5.23 and earlier.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:NAdobe Experience Manager
APPAdobe6.5< 6.5.24.0< 2025.12.0
Related vulnerabilities
Adobe Experience Manager — XXE umożliwiające RCE i odczyt plików
Adobe Experience Manager — SSRF umożliwiający zdalne wykonanie kodu
Stored XSS w Adobe Experience Manager Forms JEE – krytyczna podatność
DOM-based XSS w Adobe Experience Manager umożliwiający RCE
DOM-based XSS w Adobe Experience Manager — możliwe RCE i przejęcie sesji