Impact
Adobe Campaign Classic contains an OS command injection vulnerability caused by improper neutralization of special elements. Attackers can inject crafted commands that are executed with the privileges of the current user, potentially enabling arbitrary code execution. The flaw is exploitable without any user interaction and a scope change indicates that impact may extend beyond the originally affected components.
Affected Systems
All installations of Adobe Campaign Classic are susceptible unless patched. No specific version ranges are identified; any deployed instance lacking a fix should be considered vulnerable.
Risk and Exploitability
The CVSS score of 10 marks it as critical, and the EPSS score of 1% indicates a very low yet non‑zero likelihood of exploitation; the absence of a KEV listing does not reduce the risk. The likely attack vector is remote, via crafted input to the application’s command interface or API, enabling a threat actor to execute arbitrary OS commands. Because exploitation does not require interaction, exposure to external traffic makes the vulnerability highly actionable.
OpenCVE Enrichment