
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-64538 is a DOM-based Cross-Site Scripting (XSS) vulnerability in Adobe Experience Manager (AEM) that allows unauthenticated remote attackers to inject and execute malicious scripts in the context of a victim's browser. It affects AEM versions 6.5.23 and earlier (on-premises) and AEM Cloud Service versions prior to 2025.12.0. The vulnerability was published on December 10, 2025, with Adobe releasing the advisory (APSB25-115) on December 9, 2025. It carries a CVSS v3.1 base score of 9.3 (Critical) (Adobe Advisory, Feedly).
The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-site Scripting), specifically the DOM-based variant, meaning the malicious payload is processed and executed entirely within the browser's DOM without necessarily being reflected from the server. An attacker crafts a malicious web page or link that, when visited by an authenticated AEM user, causes the browser to execute injected JavaScript in the AEM application's security context. No privileges are required on the attacker's side, but user interaction is required — the victim must visit or be socially engineered into visiting the crafted page. No public proof-of-concept exploit code has been identified at this time (Adobe Advisory, Feedly).
Successful exploitation enables session hijacking, allowing an attacker to steal authenticated session tokens and impersonate the victim within AEM. The changed scope (S:C) in the CVSS vector indicates the impact can extend beyond the vulnerable component itself, potentially affecting other systems or data accessible to the compromised session. Confidentiality and integrity are both rated High — sensitive content, configurations, or user data managed within AEM could be exfiltrated or tampered with — while availability is not directly impacted (Adobe Advisory, Feedly).
document.write, innerHTML, location.hash processing) that accept attacker-controlled input without proper sanitization.#) or query parameter that is read and written into the DOM unsanitized.fetch or XMLHttpRequest to external IPs); unexpected cross-origin requests originating from AEM pages.<script>, javascript:, onerror=, %3Cscript%3E); browser console errors related to Content Security Policy violations if CSP is enabled.<script> tags or JavaScript event handlers not present in authorized templates.Adobe has released patches addressing this vulnerability: upgrade AEM on-premises to version 6.5.24.0 or later, and AEM Cloud Service to 2025.12.0 or later (Adobe Advisory). As interim mitigations, organizations should implement a strict Content Security Policy (CSP) to restrict unauthorized script execution, enforce input validation and output encoding on all user-supplied data rendered in the DOM, and educate users about phishing and social engineering risks. Monitoring for anomalous session activity and suspicious URL patterns in AEM access logs is also recommended.
The Belgium Centre for Cybersecurity (CCB) issued a warning advising organizations to patch immediately, characterizing the vulnerability as critical XSS in AEM (CCB Advisory). CISA referenced the vulnerability in its weekly bulletin (SB25-349). Coverage has been largely limited to automated vulnerability tracking platforms and national CERTs, with no significant independent researcher commentary or social media discussion identified at this time.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."