PT-2025-25115 · Adobe · Experience Manager

Published

2025-06-10

·

Updated

2025-06-16

·

CVE-2025-47049

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Adobe Experience Manager versions 6.5.22 and earlier
Description The issue is a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this problem by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. To exploit this issue, it is necessary for the victim to visit a specially crafted web page.
Recommendations For Adobe Experience Manager versions 6.5.22 and earlier, update to a version that contains a fix for this issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Weakness Enumeration

Related Identifiers

BDU:2025-08519
CVE-2025-47049

Affected Products

Experience Manager