Impact
Adobe Campaign Classic is affected by a Server‑Side Request Forgery vulnerability that allows an attacker to send arbitrary HTTP requests to internal or external services from the server. The flaw can be leveraged to execute arbitrary code in the context of the user running the application, leading to a full compromise of the application and potentially the underlying host. The weakness corresponds to CWE‑918, which can grant attackers the ability to instruct the server to reach addresses outside the intended scope, bypassing network isolation and enabling code execution.
Affected Systems
The vulnerability affects Adobe Campaign Classic from Adobe. No specific version range is listed in the advisory, so all deployed instances of this product should be checked for applicability.
Risk and Exploitability
The CVSS score of 10 indicates a critical severity. With no EPSS score available, the exploitation probability is uncertain, but the lack of user interaction requirement and scope change mean that a compromised site can be fully taken over. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is an unauthenticated or low‑privilege attacker triggering the SSRF endpoint, which then forces the server to contact a malicious host that delivers payloads leading to code execution.
OpenCVE Enrichment