Impact
Adobe Campaign Classic contains an Improper Control of Generation of Code flaw (CWE‑94). An attacker can cause the application to evaluate attacker‑supplied input as executable code, allowing arbitrary code execution in the context of the user who is logged in. Because the vulnerability does not require any user interaction, a low‑privileged attacker who can reach the application can run commands and potentially further exploit the system.
Affected Systems
Adobe Campaign Classic is affected. Specific product versions are not listed in the advisory, so all current installations of the platform should be treated as vulnerable until a vendor fix is applied.
Risk and Exploitability
The flaw carries a CVSS score of 9.9, indicating critical severity. EPSS data is unavailable, and the issue is not yet listed in the CISA KEV catalog. Successful exploitation would provide an attacker with the privileges of the affected user; the change in scope suggests the possibility of privilege escalation beyond the initial user context. Because no user interaction is required, the risk of exploitation is high even for simply monitoring traffic or reviewing logs.
OpenCVE Enrichment