Impact
This vulnerability is a server‑side request forgery (SSRF) that can allow an attacker to direct the affected server to make arbitrary outgoing requests. The greatest risk is privilege escalation, occurring when the exploited server has elevated rights. The fault resides in the handling of external URLs, as identified by CWE‑918. The description indicates that the vulnerability is limited to scenarios where a user visits a crafted URL or interacts with a compromised web page, so exploitation requires user interaction.
Affected Systems
Adobe Content Credentials Command‑Line Tool, Adobe Content Credentials JavaScript SDK, and Adobe Content Credentials Rust SDK are affected. No specific version numbers are supplied in the available data.
Risk and Exploitability
The CVSS score is 4.7, indicating moderate severity; however, the EPSS probability is below 1 % and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is remote, mediated by a malicious URL or compromised site that a user must access. Because the vulnerability works only after user interaction, the chance of a large‑scale exploitation is low but not impossible if a target is tricked into visiting a malicious link. If successful, the attacker may bypass controls and gain additional privileges on the affected system.
OpenCVE Enrichment