CVE-2022-42343
בינונית 6.5
תיאור (מקור, אנגלית)
Adobe Campaign version 7.3.1 (and earlier) and 8.3.9 (and earlier) are affected by a Server-Side Request Forgery (SSRF) vulnerability that could lead to arbitrary file system read. A low-privilege authenticated attacker can force the application to make arbitrary requests via injection of arbitrary URLs. Exploitation of this issue does not require user interaction.
מדדים
- CVSS 3.1
-
6.5 (MEDIUM)
מקור הציון: CNA
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N - EPSS — סבירות ניצול
- 1% (אחוזון 100) נכון ל-19/8/2026
- CWE
- CWE-918
מוצרים מושפעים
adobe: campaign; linux: linux kernel; microsoft: windows
קישורים
- https://helpx.adobe.com/security/products/campaign/apsb22-58.html Vendor Advisory
- https://helpx.adobe.com/security/products/campaign/apsb22-58.html Vendor Advisory