Vulnerability Details CVE-2021-40745
Adobe Campaign version 21.2.1 (and earlier) is affected by a Path Traversal vulnerability that could lead to reading arbitrary server files. By leveraging an exposed XML file, an unauthenticated attacker can enumerate other files on the server.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.018
EPSS Ranking 82.1%
CVSS Severity
CVSS v3 Score 7.5
CVSS v2 Score 5.0
Products affected by CVE-2021-40745
-
cpe:2.3:a:adobe:campaign:-
-
cpe:2.3:a:adobe:campaign:16.4
-
cpe:2.3:a:adobe:campaign:18.10.5.8984
-
cpe:2.3:a:adobe:campaign:21.2.1
-
cpe:2.3:a:adobe:campaign:6.11
-
cpe:2.3:a:adobe:campaign:7.2.1
-
cpe:2.3:a:adobe:campaign:7.2.2
-
cpe:2.3:a:adobe:campaign:7.3.1
-
cpe:2.3:a:adobe:campaign:7.3.2
-
cpe:2.3:a:adobe:campaign:8.0.0
-
cpe:2.3:a:adobe:campaign:8.1.14
-
cpe:2.3:a:adobe:campaign:8.1.20
-
cpe:2.3:a:adobe:campaign:8.2.10
-
cpe:2.3:a:adobe:campaign:8.2.8
-
cpe:2.3:a:adobe:campaign:8.3.8
-
cpe:2.3:a:adobe:campaign:8.3.9
-
cpe:2.3:a:adobe:campaign:8.4.1
-
cpe:2.3:a:adobe:campaign:8.4.2
-
cpe:2.3:o:linux:linux_kernel:-
-
cpe:2.3:o:microsoft:windows:-