Impact
Adobe Campaign Classic is vulnerable to an incorrect authorization flaw that can lead to arbitrary code execution in the context of the affected user. The flaw allows an attacker to execute code without relying on user interaction, potentially granting full system compromise. The weakness is classified as CWE‑863, indicating that insufficient authorization checks are present within the application.
Affected Systems
Adobe Campaign Classic installations are affected. No specific version range is provided, so all deployments should assume the vulnerability is present until a vendor update is applied.
Risk and Exploitability
The CVSS score of 10 indicates a critical risk, and exploitation does not require user interaction, implying that a remote attacker can trigger the vulnerability directly. The EPSS score is not available, and the issue is not listed in the CISA KEV catalog. The scope change indicates that the flaw can affect all users of the system, potentially escalating from a single compromised account to full administrative control. The attack vector is inferred to be remote, via the web interface, given that no user interaction is required.
OpenCVE Enrichment