Executive brief
Adobe Campaign Classic, a marketing automation platform used by enterprises, is vulnerable to SQL injection attacks that allow a low-privileged attacker to execute arbitrary code without user interaction. An attacker with limited permissions could bypass access controls and execute commands with the privileges of the vulnerable application, potentially accessing or modifying sensitive customer data and campaign information stored in the platform's database.
Technical details
The vulnerability is an improper neutralization of special characters in SQL commands, allowing SQL injection. A low-privileged attacker can craft malicious SQL to execute arbitrary code in the context of the database and application user. No user interaction is required; exploitation occurs over the network through the application's query interface.
Affected products
- Adobe Campaign Classic
Timeline
- 2026-09-22: disclosed