Impact
Adobe Campaign Classic has a violation of secure design principles that permits a security feature bypass; an attacker can use this flaw to gain unauthorized read access to data. The weakness is a failure to enforce proper security constraints, allowing privileged operations to be performed without appropriate checks. The impact includes potential exposure of confidential information and could compromise the integrity of the system's data safeguarding.
Affected Systems
Adobe:Adobe Campaign Classic is impacted. No specific version information is listed, so all deployed instances are presumed vulnerable until a patch is applied.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity level. Exploitation does not require user interaction, implying that an attacker can trigger the vulnerability remotely, potentially from any network-connected location that can reach the application. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting no publicly known exploits yet, but the high score and lack of user interaction mean the risk is significant. The attack path is likely to involve sending crafted requests to the application that bypass normal security controls, thus giving unauthorized read capability.
OpenCVE Enrichment