Adobe Campaign Classic Server-Side Request Forgery Arbitrary file system read
CVE-2022-42343
6.5MEDIUM
What is CVE-2022-42343?
Adobe Campaign version 7.3.1 (and earlier) and 8.3.9 (and earlier) are affected by a Server-Side Request Forgery (SSRF) vulnerability that could lead to arbitrary file system read. A low-privilege authenticated attacker can force the application to make arbitrary requests via injection of arbitrary URLs. Exploitation of this issue does not require user interaction.
Affected Version(s)
Adobe Campaign Classic (ACC) <= 7.3.1
Adobe Campaign Classic (ACC) <= 8.3.9
Adobe Campaign Classic (ACC) <= unspecified