Junglewise Threat Intelligence

CVE-2025-64542: Adobe Experience Manager DOM-based XSS

CVE-2025-64542 · Severity: medium · CVSS 5.4 · Published 2026-09-08

Vendors: Adobe.

Executive brief

Adobe Experience Manager, a widely-used web content management platform, contains a DOM-based cross-site scripting (XSS) vulnerability that allows attackers to inject malicious JavaScript code. An attacker could trick users into visiting a crafted webpage, causing their browser to execute malicious scripts within the Experience Manager environment. This could lead to theft of session credentials, unauthorized actions, or data exfiltration from the victim's account.

Technical details

The vulnerability is a DOM-based XSS flaw in Adobe Experience Manager where user-controlled input is improperly sanitized before being used to modify the DOM. An attacker can craft a malicious URL or webpage that, when visited by an authenticated or unauthenticated user, executes arbitrary JavaScript in the victim's browser within the context of the Experience Manager application. Exploitation requires user interaction (social engineering or phishing to click a link). The impact includes session hijacking, credential theft, and unauthorized administrative actions depending on the victim's privileges.

Affected products

  • Adobe Experience Manager

Timeline

  • 2026-09-08: disclosed

References