DOM-Based Cross-Site Scripting Vulnerability in Adobe Experience Manager
CVE-2025-64538
9.3CRITICAL
What is CVE-2025-64538?
Adobe Experience Manager versions 6.5.23 and earlier contain a DOM-based Cross-Site Scripting vulnerability that enables attackers to inject malicious scripts into web pages. This exploitation can result in arbitrary code execution within the context of a victim's browser. A successful attack requires the targeted user to visit a crafted malicious page, potentially leading to session hijacking and affecting the confidentiality and integrity of sensitive data.
Affected Version(s)
Adobe Experience Manager 0 <= 6.5.23