ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Input Validation vulnerability that could result in a security feature bypass. A high-privileged attacker could leverage this vulnerability to bypass security protections and gain unauthorized read access. Exploitation of this issue does not require user interaction and scope is changed.
2025-04-08T20:15:27.527
2025-04-23T16:44:53.987
Analyzed
CVSSv3.1: 6.8 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | adobe | coldfusion | 2021 | Yes |
Application | adobe | coldfusion | 2021 | Yes |
Application | adobe | coldfusion | 2021 | Yes |
Application | adobe | coldfusion | 2021 | Yes |
Application | adobe | coldfusion | 2021 | Yes |
Application | adobe | coldfusion | 2021 | Yes |
Application | adobe | coldfusion | 2021 | Yes |
Application | adobe | coldfusion | 2021 | Yes |
Application | adobe | coldfusion | 2021 | Yes |
Application | adobe | coldfusion | 2021 | Yes |
Application | adobe | coldfusion | 2021 | Yes |
Application | adobe | coldfusion | 2021 | Yes |
Application | adobe | coldfusion | 2021 | Yes |
Application | adobe | coldfusion | 2021 | Yes |
Application | adobe | coldfusion | 2021 | Yes |
Application | adobe | coldfusion | 2021 | Yes |
Application | adobe | coldfusion | 2021 | Yes |
Application | adobe | coldfusion | 2021 | Yes |
Application | adobe | coldfusion | 2021 | Yes |
Application | adobe | coldfusion | 2023 | Yes |
Application | adobe | coldfusion | 2023 | Yes |
Application | adobe | coldfusion | 2023 | Yes |
Application | adobe | coldfusion | 2023 | Yes |
Application | adobe | coldfusion | 2023 | Yes |
Application | adobe | coldfusion | 2023 | Yes |
Application | adobe | coldfusion | 2023 | Yes |
Application | adobe | coldfusion | 2023 | Yes |
Application | adobe | coldfusion | 2023 | Yes |
Application | adobe | coldfusion | 2023 | Yes |
Application | adobe | coldfusion | 2023 | Yes |
Application | adobe | coldfusion | 2023 | Yes |
Application | adobe | coldfusion | 2023 | Yes |
Application | adobe | coldfusion | 2025 | Yes |