Executive brief
Adobe Campaign Classic is an enterprise email marketing and customer relationship management platform used to manage customer communications. A SQL injection vulnerability allows attackers to execute arbitrary code within the application's context without requiring user interaction, potentially compromising sensitive marketing data and customer information managed by the platform.
Technical details
Adobe Campaign Classic contains an SQL injection vulnerability in improper neutralization of special elements used in SQL commands. The vulnerability allows an attacker to inject arbitrary SQL code, leading to arbitrary code execution in the context of the current user. No user interaction is required for exploitation, though successful exploitation depends on conditions beyond the attacker's control. The attack vector is network-based, and the scope is changed (impact extends beyond the affected component).
Affected products
- Adobe Campaign Classic
Timeline
- 2026-08-11: disclosed