Impact
The vulnerability is an improper neutralization of special elements used in an OS command, allowing an attacker to inject arbitrary commands. This can lead to execution of code in the context of the current user, even without any user interaction. The change of scope indicates that the impact may extend beyond the original context.
Affected Systems
Adobe Campaign Classic is the affected product. No specific versions are listed in the CNA data, so the vulnerability could potentially affect any deployed instance of Adobe Campaign Classic until patched.
Risk and Exploitability
The CVSS score of 10 indicates critical severity. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog, but the lack of exploitation data does not diminish the risk. The attack likely exploits a command injection point exposed by Adobe Campaign Classic through web or API interfaces; based on the description, it is inferred that an attacker could trigger the flaw remotely without needing to log in. Once injected, code runs in the context of the current user, allowing arbitrary action and potentially full control of the host.
OpenCVE Enrichment