CVE-2025-64538

9.3

Adobe · Experience Manager

Adobe Experience Manager versions 6.5.23 and earlier are vulnerable to DOM-based XSS, potentially allowing for session takeover and arbitrary script execution in a victim's browser context.

Executive summary

Adobe Experience Manager versions 6.5.23 and earlier are susceptible to a critical DOM-based Cross-Site Scripting vulnerability that enables session hijacking and arbitrary code execution.

Vulnerability

This is a DOM-based Cross-Site Scripting (CWE-79) vulnerability that allows unauthenticated attackers to inject malicious scripts into web pages. The scripts execute within the context of a victim's browser session, requiring the victim to interact with a crafted malicious page.

Business impact

The ability to perform session takeover poses a severe risk to organizational data and system integrity. Because this vulnerability facilitates arbitrary code execution within the user's browser, an attacker can bypass standard authentication controls to access sensitive information or perform unauthorized actions on behalf of the user. With a CVSS score of 9.3, this flaw is categorized as critical, necessitating an immediate response to prevent potential compromise of high-value administrative or user accounts.

Remediation

Immediate Action: Update Adobe Experience Manager to the latest version as specified in the official Adobe security bulletin APSB25-115.

Proactive Monitoring: Review web server and application access logs for unusual patterns, such as suspicious parameters containing script tags or abnormal referral headers.

Compensating Controls: Deploy a Web Application Firewall (WAF) with updated rulesets designed to detect and block common XSS injection patterns.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Given the critical nature of this vulnerability and the potential for complete session compromise, administrators should prioritize applying the vendor-supplied update immediately. Ensure that all instances of Adobe Experience Manager are patched, and verify that appropriate security headers are implemented to mitigate the impact of potential cross-site scripting attacks.

More Adobe CVEs all →

History

  1. Disclosed CVE record published
  2. Published in the daily brief critical section
  3. Analyst report written

Sources