Impact
Adobe Campaign Classic is vulnerable to a server‑side request forgery that can lead to privilege escalation. The flaw allows an attacker to instruct the application to make arbitrary HTTP requests, potentially to internal resources, and the affected scope is changed, meaning the attacker could gain higher privileges than the application’s normal permissions.
Affected Systems
Adobe Campaign Classic is the only product listed as affected; no specific version ranges are supplied in the available data, so all installations of Adobe Campaign Classic should be considered at risk until a vendor fix is released.
Risk and Exploitability
The CVSS score of 9.9 indicates critical severity. The EPSS score is not available, so current exploitation probability is unknown. The vulnerability is not listed in CISA's KEV catalog. Based on the description, it is inferred that the attack vector is remote network-based and no user interaction is required, implying that an attacker could exploit the flaw from outside the organization if they can reach the application. The scope change indicates that exploitation could affect broader system components or other users.
OpenCVE Enrichment