Impact
An attacker can exploit an Improper Neutralization of Special Elements used in an SQL Command in Adobe Campaign Classic to execute arbitrary SQL commands. The flaw allows the attacker to run any SQL statement in the context of the current user, potentially leading to elevated privileges or full control of the application. The vulnerability is classified as a SQL injection (CWE‑89) with a scope change, meaning it could affect the entire system beyond the compromised component.
Affected Systems
Adobe's Campaign Classic product is affected. No specific versions or sub‑products are listed in the available data, so all deployments of Adobe Campaign Classic are considered at risk until a patch is applied or a work‑around is implemented.
Risk and Exploitability
The CVSS score of 10 indicates the highest severity, and exploitation does not require any user interaction, implying it can be carried out remotely. The EPSS score is not available, so no exact probability is provided, but the absence of user interaction means an attacker can likely launch the attack without any additional preparatory steps. Because the vulnerability increases privilege within the application, it is a critical risk for any environment that hosts Adobe Campaign Classic.
OpenCVE Enrichment