Impact
Adobe Campaign Classic is affected by a Server‑Side Request Forgery vulnerability that can be exploited without user interaction; the flaw allows an attacker to craft requests that the server will forward to arbitrary internal or external hosts, potentially leading to privilege escalation within the environment. The impact is therefore a serious compromise of confidentiality and integrity, and the description states the attack can modify the privileged scope of the compromised system.
Affected Systems
All versions of Adobe Campaign Classic are impacted, as the CNA has not restricted the vulnerability to specific releases. No version information is available in the CNA data, so any installation of ACC is considered vulnerable until a patch is applied.
Risk and Exploitability
The CVSS score of 10 indicates maximum severity, and the EPSS score is not available, meaning the likelihood of exploitation cannot be quantified but the lack of user interaction and the successful scope change suggest a high potential for exploitation. Because the vulnerability is listed as not in CISA’s KEV catalog, no public exploits are confirmed; however, the likely attack vector is a network attacker sending crafted requests to the vulnerable server, potentially exploiting internal network services.
OpenCVE Enrichment