CVE-2025-64539: Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)
Adobe Experience Manager versions 6.5.23 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could lead to arbitrary code execution. An attacker could exploit this vulnerability by injecting malicious scripts into a web page that are executed in the context of the victim's browser. A successful attacker can abuse this to achieve session takeover, increasing the confidentiality and integrity impact as high. Exploitation of this issue requires user interaction in that a victim must visit a crafted malicious page.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-64539?
CVE-2025-64539 has a high severity rating due to the potential for arbitrary code execution.
How do I fix CVE-2025-64539?
To fix CVE-2025-64539, update Adobe Experience Manager to version 6.5.24 or later.
What types of attacks can exploit CVE-2025-64539?
CVE-2025-64539 can be exploited through DOM-based Cross-Site Scripting (XSS) attacks that allow script injection.
Which versions of Adobe Experience Manager are affected by CVE-2025-64539?
CVE-2025-64539 affects Adobe Experience Manager versions 6.5.23 and earlier.
What are the potential impacts of CVE-2025-64539?
The potential impacts of CVE-2025-64539 include unauthorized access, data exfiltration, or full system compromise.