Executive brief
Adobe Campaign Classic, a customer relationship management platform used for marketing automation and campaign management, is vulnerable to SQL injection attacks. An attacker with elevated privileges can execute arbitrary SQL commands to manipulate or extract data from the database, potentially compromising customer records and business operations without any user interaction required.
Technical details
An improper neutralization of special characters in SQL commands allows a high-privilege attacker to inject malicious SQL code and execute arbitrary commands within the database context of the application. The vulnerability requires the attacker to already possess elevated privileges and has a changed security scope indicating potential privilege escalation or impact boundary modifications. No user interaction is necessary to exploit this flaw.
Affected products
- Adobe Campaign Classic
Timeline
- 2026-09-22: disclosed