Impact
The vulnerability is an SQL injection that allows execution of arbitrary SQL commands, resulting in arbitrary code execution in the context of the current user. Attackers with high privileges could use the flaw to run arbitrary code, and the flaw arises from improper neutralization of special characters in SQL statements (CWE-89).
Affected Systems
Adobe Campaign Classic installations are affected. No specific version numbers are provided, so all deployments that have not applied Adobe’s security patch should be treated as vulnerable.
Risk and Exploitability
The CVSS score of 9.1 signals critical severity. Because exploitation does not require user interaction and the scope is changed, a high‑privilege attacker who can access the application can compromise the instance. The EPSS score is not available, and the vulnerability is not listed in CISA KEV, but the lack of those metrics does not diminish the risk posed by the able exploitation path.
OpenCVE Enrichment