Impact
Adobe Campaign Classic is vulnerable to an improper control of code generation flaw that permits attackers to inject and execute arbitrary code under the permissions of the current user. The vulnerability stems from insecure handling of user-supplied input in dynamic code contexts, leading to a code injection weakness. An attacker exploiting this flaw can run arbitrary programs on the affected instance, potentially compromising confidentiality, integrity, and availability of data and services within the scope of the compromised application.
Affected Systems
The affected product is Adobe Campaign Classic as distributed by Adobe. No specific version list is provided in the CNA data, so all currently deployed installations of Adobe Campaign Classic are at risk until a vendor update is applied.
Risk and Exploitability
The flaw carries a CVSS score of 10, indicating the highest level of severity. No EPSS score is available, but the lack of user interaction and scope changes suggest the vulnerability can be leveraged remotely by an unauthenticated or authenticated adversary depending on their privileges. Because it is not listed in CISA’s KEV catalog, no actively deployed exploit is confirmed; however, the combination of a high impact rating and the potential for remote exploitation makes it a high-priority target for attackers.
OpenCVE Enrichment