Impact
Adobe Campaign Classic contains an Improper Input Validation flaw that allows a low‑privileged attacker to execute arbitrary code in the context of the authenticated user. The flaw does not require user interaction and the scope is changed, meaning that once exploited the attacker can gain broader system access. Because the vulnerability permits arbitrary code execution, the potential loss includes full compromise of the campaign service, disclosure or loss of customer data, and irrecoverable availability impact.
Affected Systems
Adobe Campaign Classic installations are vulnerable. No specific version ranges are listed in the advisory, so all deployed instances should be assessed. The advisory references Adobe’s security bulletin, but does not provide version qualifiers.
Risk and Exploitability
The CVSS score of 9.9 indicates critical severity. While no EPSS score is available, the lack of a KEV listing does not negate the risk. Attackers can exploit the flaw by injecting malformed input into the application without needing any user interaction. Because the vulnerability changes scope, an attacker with minimal privileges can elevate privileges and affect the entire system. The exploit is straightforward, suggesting a high likelihood of real‑world exploitation if not immediately remediated.
OpenCVE Enrichment