CVE-2025-64562
Unknown Unknown - Not Provided
BaseFortify

Publication date: 2025-12-10

Last updated on: 2025-12-12

Assigner: Adobe Systems Incorporated

Description
Adobe Experience Manager versions 6.5.23 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be exploited by a low privileged attacker to execute malicious scripts in the context of the victim's browser. Exploitation of this issue requires user interaction, such as visiting a crafted URL or interacting with a manipulated web page.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2025-12-10
Last Modified
2025-12-12
Generated
2026-05-27
AI Q&A
2025-12-10
EPSS Evaluated
2026-05-25
NVD
Affected Vendors & Products
Showing 2 associated CPEs
Vendor Product Version / Range
adobe experience_manager to 6.5.24.0 (inc)
adobe experience_manager 6.5.23
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

This vulnerability is a DOM-based Cross-Site Scripting (XSS) issue in Adobe Experience Manager versions 6.5.23 and earlier. It allows a low privileged attacker to execute malicious scripts in the victim's browser by tricking the user into interacting with a crafted URL or manipulated web page.


How can this vulnerability impact me? :

The vulnerability can lead to execution of malicious scripts in the context of a victim's browser, potentially allowing attackers to steal sensitive information, hijack user sessions, or perform actions on behalf of the user. Exploitation requires user interaction.


What immediate steps should I take to mitigate this vulnerability?

To mitigate this vulnerability, you should update Adobe Experience Manager to a version later than 6.5.23. Additionally, educate users to avoid interacting with suspicious URLs or manipulated web pages that could trigger the DOM-based XSS exploit.


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart