Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction.
2022-10-14T20:15:12.507
2024-11-21T07:16:26.210
Modified
CVSSv3.1: 9.8 (CRITICAL)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | adobe | coldfusion | 2018 | Yes |
Application | adobe | coldfusion | 2018 | Yes |
Application | adobe | coldfusion | 2018 | Yes |
Application | adobe | coldfusion | 2018 | Yes |
Application | adobe | coldfusion | 2018 | Yes |
Application | adobe | coldfusion | 2018 | Yes |
Application | adobe | coldfusion | 2018 | Yes |
Application | adobe | coldfusion | 2018 | Yes |
Application | adobe | coldfusion | 2018 | Yes |
Application | adobe | coldfusion | 2018 | Yes |
Application | adobe | coldfusion | 2018 | Yes |
Application | adobe | coldfusion | 2018 | Yes |
Application | adobe | coldfusion | 2018 | Yes |
Application | adobe | coldfusion | 2018 | Yes |
Application | adobe | coldfusion | 2018 | Yes |
Application | adobe | coldfusion | 2021 | Yes |
Application | adobe | coldfusion | 2021 | Yes |
Application | adobe | coldfusion | 2021 | Yes |
Application | adobe | coldfusion | 2021 | Yes |
Application | adobe | coldfusion | 2021 | Yes |