Impact
Adobe Campaign Classic is vulnerable to improper neutralization of special elements in an SQL command, resulting in a classic SQL injection flaw. The flaw can allow an attacker to inject and execute arbitrary SQL, which is capable of being leveraged to run arbitrary code within the context of the current user. The impact is therefore the potential for remote code execution, with the risk that an attacker could use the injection to alter data or compromise the underlying system.
Affected Systems
The affected product is Adobe Campaign Classic from Adobe. No specific version information is listed in the CNA data, so all released versions of the product are potentially at risk until the vendor issues a fix.
Risk and Exploitability
The CVSS score of 9 indicates a high severity flaw. The EPSS score is less than 1%, suggesting that the probability of exploitation in the wild is low but not zero. The vulnerability is not listed in CISA's KEV catalog. Although exploitation does not require user interaction, the attack vector is inferred to be through the web interface of the product, which accepts user-supplied input that is incorporated into database queries. The "Scope changed" qualifier implies that the attacker could gain privileges beyond the current user if exploitation is successful.
OpenCVE Enrichment