CRITICAL🇬🇧 English

CVE-2026-48381

CVSS 9.0v3.1pub. 2026-08-11upd. 2026-08-28

Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue does not require user interaction. Scope is changed.

oryginał EN
CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
  • Adobe Campaign

    APP
    Adobe
    7.2.1 – 7.4.4 (bez)
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
Tagi
RCESQLi
CWE
Referencje

Powiązane podatności

CVE-2026-71398CRITICAL10.0ten sam produkt

Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbi...

CVE-2026-27302CRITICAL10.0ten sam produkt

Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbi...

CVE-2026-48326CRITICAL9.9PL ✓ten sam produkt

SQL Injection umożliwiający RCE w Adobe Campaign Classic

CVE-2026-48317CRITICAL9.6PL ✓ten sam produkt

Adobe Campaign Classic — Eval Injection umożliwiający RCE

CVE-2026-48323CRITICAL10.0PL ✓ten sam produkt

Adobe Campaign Classic — RCE przez podatność silnika szablonów (SSTI)