Impact
Adobe Campaign Classic is vulnerable to an SQL injection flaw caused by improper neutralization of special characters in database queries. This flaw permits an attacker to execute arbitrary SQL commands, potentially exposing sensitive memory contents and enabling read access to the file system. No user interaction is required and the vulnerability changes the scope, meaning that successful exploitation could affect more components of the application or underlying system. The result is a significant data disclosure threat that could be leveraged for further compromise.
Affected Systems
The vulnerability affects Adobe Campaign Classic installations from Adobe. No specific product version information is provided, so all current deployments of the product are potentially vulnerable.
Risk and Exploitability
The CVSS score of 8.6 signals high severity, and the EPSS score of less than 1% indicates a low probability of exploitation at the moment. However, the scope change elevates the impact that could arise once the flaw is exploited. The vulnerability is not listed in the CISA KEV catalog. Attackers are likely able to trigger the SQL injection via remote network traffic directed at the application, since no user interaction is required.
OpenCVE Enrichment