Impact
Adobe Campaign Classic suffers from an SQL injection due to improper neutralization of special elements, enabling a low‑privileged attacker to execute arbitrary SQL commands that can be converted into code running with the credentials of the current user. The vulnerability allows changes in scope and can lead to full compromise of the affected system. Based on the description, it is inferred that the attack could be performed remotely without user interaction.
Affected Systems
Adobe Campaign Classic is the product affected; version details are not disclosed in the available data.
Risk and Exploitability
The CVSS score of 9.9 indicates critical severity, but the EPSS score is unavailable and the issue is not listed in CISA’s KEV catalog, suggesting limited public exploitation evidence. Nevertheless, because no user interaction is required and the flaw leads to arbitrary code execution, it can be inferred that attackers could automate the exploit remotely; the change in scope means that privilege escalation is possible from low to higher authority within the application.
OpenCVE Enrichment