Impact
The vulnerability is an improper neutralization of special elements in an SQL command, allowing SQL injection that can bypass security features. It could give a low‑privileged attacker read and limited write access without user interaction, and the scope change means the attacker can affect data beyond the targeted component.
Affected Systems
Adobe Campaign Classic is the affected product. No specific version information is provided, so all installations of Adobe Campaign Classic remain potentially vulnerable until a patch is applied.
Risk and Exploitability
The CVSS score of 9.1 indicates critical severity. The EPSS score is unavailable, so the current exploitation probability cannot be quantified, but the absence of a KEV listing suggests no known active exploitation yet. Based on the description, the likely attack vector is through the application’s web interface or internal API exposed to local or remote users; attackers do not need user interaction, implying the vulnerability can be triggered remotely. The ability to modify read/write access elevates the risk to confidentiality and integrity of the application’s data.
OpenCVE Enrichment