External risk intelligence

Adobe Experience Manager DOM-based XSS Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2025-64539

Adobe Experience Manager is widely deployed as a public-facing web content management system or web application platform. This vulnerability involves DOM-based XSS, which is commonly encountered when users interact with externally reachable web pages and applications built on this product.

Cross-site Scripting

Adobe Experience Manager

before 6.5.24.0before 2025.12.06.5

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory highlights a critical vulnerability in Adobe Experience Manager that could allow attackers to execute malicious code within a user's browser, potentially leading to the complete compromise of user sessions. Exploitation requires a user to interact with a specially crafted web page, but the severity of the potential impact, including unauthorized access to and modification of sensitive information, warrants attention.

  • Flaw allows attackers to run malicious code in user browsers.
  • Compromised sessions increase data confidentiality and integrity risks.
  • Confirming relevance and exposure is the primary leadership concern.

Attack Path

How an attacker could exploit the issue

An attacker can exploit this vulnerability by tricking a user into visiting a malicious web page. This page contains specially crafted scripts that, when loaded in the user's browser, execute within the context of Adobe Experience Manager. This allows the attacker to take over the user's session, leading to high impact on confidentiality and integrity.

  • Requires user interaction to visit a crafted page.
  • Involves injecting malicious scripts into a web page.
  • Can lead to session takeover.

Live Threat

Current exploitation, exposure, and threat context

A DOM-based Cross-Site Scripting vulnerability could allow an attacker to execute arbitrary code in a user's browser when they visit a specially crafted web page. This could lead to the attacker taking over the user's session, impacting the confidentiality and integrity of their interactions.

  • User session data at risk.
  • Via crafted malicious web pages.
  • Session takeover and data integrity compromise.

Operational Fix

Recommended remediation, mitigation, and detection steps

Teams responsible for maintaining Adobe Experience Manager, including platform and application owners, should prioritize addressing this DOM-based XSS vulnerability. The initial step involves identifying all instances of the affected technology within the environment, assessing their exposure and business criticality, and confirming the accountable owner for each. Subsequently, a remediation plan should be developed based on the identified risks, considering potential impacts on confidentiality and integrity, and requiring user interaction for exploitation.

  • Platform and application owners should address this.
  • Verify exposure and business criticality first.
  • Plan remediation based on identified risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Adobe Experience Manager?

Adobe Experience Manager is a comprehensive content management system used by organizations to build, manage, and deliver digital experiences across websites, mobile apps, and other platforms. It acts as a central hub for digital assets and content publishing, often serving as the foundation for both public-facing marketing sites and internal portals that store sensitive user interactions.

What is the nature of the CVE-2025-64539 vulnerability?

This vulnerability is a DOM-based Cross-Site Scripting (XSS) flaw, categorized as CWE-79. It occurs when a web application processes data from the browser's Document Object Model in an unsafe way. By injecting malicious scripts into a page, an attacker can trick the browser into executing that code as if it were legitimate, effectively hijacking the user's session and gaining access to their interactions.

How is this vulnerability triggered?

An attacker must successfully induce a user to navigate to a specifically crafted malicious web page. The vulnerability is not triggered by simply having the software installed or by an attacker directly probing the server; it requires the victim's active participation through browser interaction. If a user does not visit the malicious content, the script will not execute.

Is my organization at risk from this AEM vulnerability?

According to Halo Surface Signal, this vulnerability is particularly relevant to systems that are internet-facing. Because this is a DOM-based XSS issue, instances of Adobe Experience Manager that serve public web content or are frequently accessed by users via the internet carry a higher likelihood of being targeted compared to strictly internal, isolated applications.

What steps should I take to respond to this advisory?

Begin by cataloging all deployed instances of Adobe Experience Manager to understand where this technology exists in your environment. Once identified, evaluate the business criticality and exposure level of each instance. Finally, coordinate with your technical team to develop a remediation plan that prioritizes those systems with the highest potential for user interaction and sensitive data handling.

References