Impact
Adobe Campaign Classic suffers from an Improper Control of Generation of Code vulnerability that allows an attacker to inject and execute arbitrary code with the privileges of the current user. The weakness is a code injection flaw (CWE‑94) and does not require user interaction, with the attack changing the scope of the vulnerability.
Affected Systems
The affected product is Adobe Campaign Classic from Adobe. No specific version numbers are listed; any deployments of ACC should verify whether they have applied the available security patch.
Risk and Exploitability
The CVSS score of 10 indicates a critical severity. The EPSS score is not available, and the vulnerability is not listed in CISA KEV, but the lack of a KEV status does not reduce the risk. Exploitation can occur remotely with no user interaction, so the potential for widespread impact is high. Immediate patching is strongly recommended.
OpenCVE Enrichment