ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. A high-privileged attacker could leverage this vulnerability to bypass security protections and gain unauthorized read access. Exploitation of this issue does not require user interaction and scope is changed.
2025-05-13T21:16:16.390
2025-05-19T20:40:31.663
Analyzed
CVSSv3.1: 6.8 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | adobe | coldfusion | 2021 | Yes |
Application | adobe | coldfusion | 2021 | Yes |
Application | adobe | coldfusion | 2021 | Yes |
Application | adobe | coldfusion | 2021 | Yes |
Application | adobe | coldfusion | 2021 | Yes |
Application | adobe | coldfusion | 2021 | Yes |
Application | adobe | coldfusion | 2021 | Yes |
Application | adobe | coldfusion | 2021 | Yes |
Application | adobe | coldfusion | 2021 | Yes |
Application | adobe | coldfusion | 2021 | Yes |
Application | adobe | coldfusion | 2021 | Yes |
Application | adobe | coldfusion | 2021 | Yes |
Application | adobe | coldfusion | 2021 | Yes |
Application | adobe | coldfusion | 2021 | Yes |
Application | adobe | coldfusion | 2021 | Yes |
Application | adobe | coldfusion | 2021 | Yes |
Application | adobe | coldfusion | 2021 | Yes |
Application | adobe | coldfusion | 2021 | Yes |
Application | adobe | coldfusion | 2021 | Yes |
Application | adobe | coldfusion | 2021 | Yes |
Application | adobe | coldfusion | 2023 | Yes |
Application | adobe | coldfusion | 2023 | Yes |
Application | adobe | coldfusion | 2023 | Yes |
Application | adobe | coldfusion | 2023 | Yes |
Application | adobe | coldfusion | 2023 | Yes |
Application | adobe | coldfusion | 2023 | Yes |
Application | adobe | coldfusion | 2023 | Yes |
Application | adobe | coldfusion | 2023 | Yes |
Application | adobe | coldfusion | 2023 | Yes |
Application | adobe | coldfusion | 2023 | Yes |
Application | adobe | coldfusion | 2023 | Yes |
Application | adobe | coldfusion | 2023 | Yes |
Application | adobe | coldfusion | 2023 | Yes |
Application | adobe | coldfusion | 2023 | Yes |
Application | adobe | coldfusion | 2025 | Yes |
Application | adobe | coldfusion | 2025 | Yes |