Impact
Adobe Campaign Classic contains a code injection flaw that allows an attacker to execute arbitrary code with the rights of the current user. The vulnerability originates from improper control of generated code and is classified as CWE‑94. Exploitation requires no user interaction and changes the scope of the affected system.
Affected Systems
The affected product is Adobe Campaign Classic (ACC) from Adobe. Version details are not specified in the advisory.
Risk and Exploitability
The CVSS score of 10 indicates the highest severity. The EPSS score is not available and the vulnerability is not listed in CISA's KEV, yet the lack of user interaction and scope change make it a critical risk for any deployed instance. Attack vectors are likely through authenticated or unauthenticated administrative interfaces, and the description does not specify the exact entry point, so the potential remains high.
OpenCVE Enrichment