Executive brief
Adobe Experience Manager, a widely-used content management system for enterprises, contains a DOM-based cross-site scripting (XSS) vulnerability that allows attackers to inject and execute malicious JavaScript code. An attacker can exploit this by tricking users into visiting a crafted webpage, potentially allowing theft of session tokens, account hijacking, or defacement of content. User interaction is required for successful exploitation.
Technical details
This is a DOM-based cross-site scripting (XSS) vulnerability in Adobe Experience Manager where untrusted data can be reflected in the DOM and executed as JavaScript. The vulnerability requires user interaction—a victim must visit an attacker-controlled webpage that crafts a payload targeting the vulnerable parameter. The vulnerability changes the scope of the application, potentially allowing an attacker to manipulate data or functionality beyond the immediate vulnerable component. A patch or update from Adobe is expected to address this issue.
Affected products
- Adobe Experience Manager
Timeline
- 2026-09-08: disclosed