← Back

CVE-2025-46959

nvd nist
Published: Jul 16, 2025Modified: Jun 17, 2026

JSON object

Loading...
5.4
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.3 / Impact: 2.7
Source: psirt@adobe.com (Secondary)

Description

Adobe Experience Manager versions 6.5.22 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. A low privileged attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a specially crafted web page.

Affected (2)

1 product
Experience Manager
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Adobe
Before 6.5.23.0
Before 2025.5

References (1)

Timeline

No history available yet.