Impact
This vulnerability is an Improper Input Validation flaw that allows an attacker to bypass security controls and gain unauthorized write access. The weakness, classified as CWE-20, can be exploited by providing malformed input that the system fails to validate correctly. If successful, the attacker can modify or create data beyond the intended permissions, potentially compromising data integrity and availability.
Affected Systems
Adobe Content Credentials Command-Line Tool, Adobe Content Credentials JavaScript SDK, and Adobe Content Credentials Rust SDK are affected. No specific version numbers are listed, so all current releases of these components are considered vulnerable until a patch is applied.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. The EPSS score of less than 1% suggests a low likelihood of exploitation at this time. The vulnerability is not currently listed in CISA’s KEV catalog. Exploitation requires user interaction; a victim must open a maliciously crafted URL or interact with a compromised web page. Thus the attack surface is limited to phishing or social engineering vectors and is not remotely exploitable without user action.
OpenCVE Enrichment