Vulnerability Details CVE-2019-7847
Adobe Campaign Classic version 18.10.5-8984 and earlier versions have an Improper Restriction of XML External Entity Reference ('XXE') vulnerability. Successful exploitation could lead to Arbitrary read access to the file system in the context of the current user.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.012
EPSS Ranking 77.6%
CVSS Severity
CVSS v3 Score 7.5
CVSS v2 Score 5.0
Products affected by CVE-2019-7847
-
cpe:2.3:a:adobe:campaign:-
-
cpe:2.3:a:adobe:campaign:18.10.5.8984
-
cpe:2.3:a:adobe:campaign:7.2.1
-
cpe:2.3:a:adobe:campaign:7.2.2
-
cpe:2.3:a:adobe:campaign:7.3.1
-
cpe:2.3:a:adobe:campaign:7.3.2
-
cpe:2.3:a:adobe:campaign:8.0.0
-
cpe:2.3:a:adobe:campaign:8.1.14
-
cpe:2.3:a:adobe:campaign:8.1.20
-
cpe:2.3:a:adobe:campaign:8.2.10
-
cpe:2.3:a:adobe:campaign:8.2.8
-
cpe:2.3:a:adobe:campaign:8.3.8
-
cpe:2.3:a:adobe:campaign:8.3.9
-
cpe:2.3:a:adobe:campaign:8.4.1
-
cpe:2.3:a:adobe:campaign:8.4.2
-
cpe:2.3:o:linux:linux_kernel:-
-
cpe:2.3:o:microsoft:windows:-