External risk intelligence

Adobe Experience Manager DOM-based Cross-Site Scripting Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2025-64537

Adobe Experience Manager is commonly deployed as a public-facing web content management system or web application platform. This vulnerability involves DOM-based Cross-Site Scripting, which affects client-side execution in the context of the victim's browser when accessing the web application, making it a likely target for exposure in internet-facing deployments.

Cross-site Scripting

Adobe Experience Manager

before 6.5.24.0before 2025.12.06.5

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This vulnerability in Adobe Experience Manager could allow an attacker to execute malicious code in a user's browser by tricking them into visiting a specially crafted web page. This could lead to the takeover of user sessions, significantly impacting confidentiality and integrity.

  • Malicious scripts can run in user browsers.
  • Session takeover risk impacts sensitive data.
  • Confirm relevance and exposure for this system.

Attack Path

How an attacker could exploit the issue

An attacker can target users by creating a malicious web page containing specially crafted scripts. When a user visits this page, the scripts are executed within their browser. This allows the attacker to potentially take over the user's session, leading to unauthorized access and modification of data.

  • Entry: Attacker crafts a malicious page.
  • Trigger: Victim visits the crafted page.
  • Risk: Session takeover, data compromise.

Live Threat

Current exploitation, exposure, and threat context

When supported by the advisory, this vulnerability could allow an attacker to execute arbitrary code in a victim's browser by tricking them into visiting a malicious page, potentially leading to session takeover.

  • Web application sessions at risk.
  • Malicious scripts executed in user's browser.
  • Session takeover may occur.

Operational Fix

Recommended remediation, mitigation, and detection steps

Technical leaders and security teams should coordinate with application owners to identify all Adobe Experience Manager instances. Prioritize instances exposed to the internet or accessible by untrusted users, as these pose the highest risk for session takeover and data compromise. Once critical assets are identified, plan remediation or mitigating actions during the next maintenance window.

  • Application owners should lead remediation efforts.
  • Verify internet-facing or externally accessible instances.
  • Plan and execute mitigation or patching.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Adobe Experience Manager?

Adobe Experience Manager is a comprehensive content management system used by organizations to build, manage, and deliver digital experiences across websites, mobile apps, and forms. It serves as a central platform for hosting web content and managing digital assets, often functioning as the backbone for public-facing corporate web applications.

What does CVE-2025-64537 mean by DOM-based XSS?

This refers to CWE-79, a weakness where a web application improperly handles data on the client side. In this specific CVE, the application's client-side code processes input in a way that allows an attacker to inject malicious scripts. When a browser executes these scripts, the attacker can manipulate the page content or steal sensitive session information.

How is this vulnerability triggered?

The vulnerability requires user interaction to execute. An attacker must successfully trick a legitimate user into visiting a malicious, specially crafted web page. It is not triggered by simply hosting the application; the attack occurs within the victim's browser, meaning automated scans or background requests to the server will not initiate the exploit.

Why should I care about this Adobe vulnerability?

According to the Halo Surface Signal, this software is commonly deployed as a public-facing web platform. Because the vulnerability targets client-side execution, internet-facing instances are more likely to be reachable by an attacker who could distribute a malicious link. If your users frequently access the system from external networks, the risk of session takeover is significant.

What should I do if I run this software?

Start by identifying all instances of Adobe Experience Manager within your environment, prioritizing those that are accessible from the internet. Coordinate with your application owners to review the available security updates from the vendor, plan for testing, and schedule a maintenance window to apply the necessary patches to secure your user sessions.

References