External risk intelligence

Adobe Experience Manager DOM-based XSS Vulnerability Allows Code Execution and Session Takeover

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2025-64538

Adobe Experience Manager is a web content management system commonly deployed as an internet-facing web application or public-facing portal. As a web-based platform, its interfaces are frequently exposed to the internet to serve content or provide administrative access, making it a common target for browser-based attacks in typical deployments.

Cross-site Scripting

Adobe Experience Manager

before 6.5.24.0before 2025.12.06.5

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in Adobe Experience Manager that could allow attackers to execute arbitrary code within a user's browser. This is a cross-site scripting issue that requires a user to interact with a malicious link or page to be exploited, but if successful, it could significantly compromise user sessions and data. The primary concern is to confirm if our deployment is affected and understand potential exposure.

  • Code execution risk in web content management.
  • Session takeover and data compromise are possible.
  • Confirm relevance and exposure to affected systems.

Attack Path

How an attacker could exploit the issue

An attacker can target Adobe Experience Manager by tricking a user into visiting a malicious web page. This page would contain specially crafted scripts that, when loaded by the victim's browser, could execute arbitrary code. This would allow the attacker to potentially take over the user's session.

  • Requires user interaction to visit a crafted page.
  • Injects malicious scripts into web pages.
  • Leads to session takeover and data compromise.

Live Threat

Current exploitation, exposure, and threat context

When supported by the advisory, this vulnerability could allow an attacker to inject malicious scripts into a web page, which would then execute in a victim's browser. This could lead to unauthorized session takeover, impacting the confidentiality and integrity of user data.

  • User sessions could be compromised.
  • Victims visit a crafted malicious page.
  • Unauthorized access and data modification.

Operational Fix

Recommended remediation, mitigation, and detection steps

This DOM-based XSS vulnerability in Adobe Experience Manager likely impacts platform and application teams responsible for managing content and user experiences. The initial step should be to locate all instances of the affected technology, assess their exposure and business criticality, identify the accountable owners, and then develop a remediation plan based on the identified risks.

  • Platform/Application teams own remediation.
  • Verify external reachability and business criticality.
  • Plan coordinated patching or vendor engagement.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Adobe Experience Manager?

Adobe Experience Manager is a web content management system used by organizations to build, manage, and deliver digital experiences, websites, and mobile applications. It functions as a centralized platform for hosting digital assets and public-facing content portals.

What does CVE-2025-64538 mean?

This CVE identifies a DOM-based Cross-Site Scripting (XSS) vulnerability, classified as CWE-79. It occurs when a web application processes input in an insecure way, allowing an attacker to inject malicious scripts that execute directly within a victim's browser rather than on the server itself.

How is this vulnerability triggered?

An attacker triggers the vulnerability by tricking a user into visiting a specially crafted malicious page. Simply accessing the vulnerable application normally does not trigger the bug; the malicious script execution relies entirely on the victim interacting with the attacker-controlled link.

Do I need to worry about this if my system is internal?

Halo Surface Signal indicates that because this platform is commonly deployed as an internet-facing application to serve content, it is frequently exposed to external browser-based attacks. If your AEM instance is strictly internal, the risk profile differs from public-facing portals, but you should still evaluate access controls to ensure unauthorized users cannot interact with it.

When should I take action for CVE-2025-64538?

You should begin by locating all instances of the affected software within your infrastructure to assess their criticality. Once identified, work with the accountable teams to prioritize patching based on the system's business function and exposure level.

References