{"id":"CVE-2022-42343","title":"Adobe Campaign version 7.3.1 (and earlier) and 8.3.9 (and earlier) are affected by a Server-Side Request Forgery (SSRF) vulnerability that could lead to arbitrary file system read","summary":"Adobe Campaign version 7.3.1 (and earlier) and 8.3.9 (and earlier) are affected by a Server-Side Request Forgery (SSRF) vulnerability that could lead to arbitrary file system read. A low-privilege authenticated attacker can force the app…","severity":"medium","cvss":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","cwe":["CWE-918"],"vendor":"adobe","product":"campaign","affected":["campaign < 7.3.2","campaign >= 8.0.0, < 8.4.2"],"patched":["campaign 8.4.2"],"published":"2022-12-16","updated":"2026-08-06","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2022-42343","references":[{"url":"https://helpx.adobe.com/security/products/campaign/apsb22-58.html","label":"psirt@adobe.com"},{"url":"https://helpx.adobe.com/security/products/campaign/apsb22-58.html","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd"],"epss":0.01364,"epssPercentile":0.70574,"ingestedAt":"2026-08-06T14:59:48.296Z","slug":"CVE-2022-42343","body":"## Overview\n\nAdobe Campaign version 7.3.1 (and earlier) and 8.3.9 (and earlier) are affected by a Server-Side Request Forgery (SSRF) vulnerability that could lead to arbitrary file system read. A low-privilege authenticated attacker can force the application to make arbitrary requests via injection of arbitrary URLs. Exploitation of this issue does not require user interaction.\n\n## Affected\n\n- `campaign < 7.3.2`\n- `campaign >= 8.0.0, < 8.4.2`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `campaign 8.4.2`","depth":"sunlit","depthScore":36,"depthScoreParts":{"impact":35.8,"likelihood":0.3,"exploitation":0,"ransomware":0},"changes":[]}