
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-64563 is a DOM-based Cross-Site Scripting (XSS) vulnerability in Adobe Experience Manager (AEM) that allows a low-privileged attacker to execute malicious scripts in the context of a victim's browser. It affects AEM versions 6.5.23 and earlier (on-premise) and AEM Cloud Service versions prior to 2025.12.0. The vulnerability was published on December 9–10, 2025, with a patch released the same day. It carries a CVSS v3.1 base score of 5.4 (Medium) (Adobe Advisory).
The root cause is improper neutralization of user-supplied input during web page generation (CWE-79), specifically manifesting as a DOM-based XSS flaw. An attacker with low privileges can craft a malicious URL or manipulate a web page such that, when visited by a victim, client-side JavaScript processes attacker-controlled data and injects it into the DOM without proper sanitization. Exploitation requires user interaction — the victim must visit a crafted URL or interact with a manipulated page — and the vulnerability has a changed scope, meaning the injected script executes in the context of the victim's browser session on the AEM application (Adobe Advisory, EUVD).
Successful exploitation allows an attacker to execute arbitrary JavaScript in the victim's browser session within the AEM application context, potentially leading to session token theft, credential harvesting, unauthorized actions performed on behalf of the victim, and limited data exfiltration. The changed scope means the impact extends beyond the attacker's own session, affecting confidentiality and integrity (low impact each) of the victim's interaction with the application. Availability is not directly impacted (Adobe Advisory).
/libs/granite/core/content/login.html).#<img src=x onerror=alert(document.cookie)> or a more sophisticated payload to steal session tokens) targeting the vulnerable AEM endpoint.fetch(), XMLHttpRequest, or <img> tags with external src) originating from AEM page interactions.%3Cscript%3E, onerror=, javascript:).Adobe has released patches addressing CVE-2025-64563 as part of security bulletin APSB25-115, published December 9, 2025. AEM on-premise users should upgrade to version 6.5.24.0 or later; AEM Cloud Service customers should ensure their environment is updated to the 2025.12.0 release or later. No specific configuration-based workaround is documented; upgrading to the patched version is the recommended remediation. Organizations should also consider deploying a WAF with XSS filtering rules as a defense-in-depth measure (Adobe Advisory).
The Center for Internet Security (CIS) issued an advisory noting multiple vulnerabilities in Adobe products, including this CVE, could allow for arbitrary code execution, recommending prompt patching (CIS Advisory). Tenable flagged the issue in their vulnerability pipeline shortly after disclosure. Community discussion on platforms such as Bluesky and Mastodon/CIRCL was limited, reflecting the medium severity and lack of active exploitation. No notable independent researcher commentary or detailed technical write-ups have been published beyond the vendor advisory.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."