Impact
Adobe Campaign Classic is vulnerable to a Server‑Side Request Forgery that can be triggered by a low‑privileged user without any user interaction. The flaw allows the attacker to direct the application to query arbitrary internal resources, effectively granting the attacker elevated access and the ability to read or modify sensitive data. The weakness is classified as CWE‑918, which indicates improper validation of user‑supplied URLs.
Affected Systems
Adobe Campaign Classic (ACC) from Adobe is the affected product. Specific affected versions are not listed in the advisory; organizations should verify whether their installed version is within the scope of the issue.
Risk and Exploitability
The CVSS score of 9.6 reflects a high severity and the scope change confirms that privileges can be escalated once the SSRF is exploited. EPSS data is not available, but the lack of a known KEV listing does not reduce the risk; the flaw remains exploitable in the wild if the application is accessed by a low‑privileged user. The likely attack vector is an SSRF request originating from the ACC server to internal services, which does not require user interaction and therefore can be automated.
OpenCVE Enrichment