ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could result in a security feature bypass. A high-privileged attacker could leverage this vulnerability to access sensitive information. Exploitation of this issue does not require user interaction. The vulnerable component is restricted to internal IP addresses.
2025-07-08T21:15:26.757
2025-07-11T16:46:47.730
Analyzed
CVSSv3.1: 4.5 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | adobe | coldfusion | 2021 | Yes |
Application | adobe | coldfusion | 2021 | Yes |
Application | adobe | coldfusion | 2021 | Yes |
Application | adobe | coldfusion | 2021 | Yes |
Application | adobe | coldfusion | 2021 | Yes |
Application | adobe | coldfusion | 2021 | Yes |
Application | adobe | coldfusion | 2021 | Yes |
Application | adobe | coldfusion | 2021 | Yes |
Application | adobe | coldfusion | 2021 | Yes |
Application | adobe | coldfusion | 2021 | Yes |
Application | adobe | coldfusion | 2021 | Yes |
Application | adobe | coldfusion | 2021 | Yes |
Application | adobe | coldfusion | 2021 | Yes |
Application | adobe | coldfusion | 2021 | Yes |
Application | adobe | coldfusion | 2021 | Yes |
Application | adobe | coldfusion | 2021 | Yes |
Application | adobe | coldfusion | 2021 | Yes |
Application | adobe | coldfusion | 2021 | Yes |
Application | adobe | coldfusion | 2021 | Yes |
Application | adobe | coldfusion | 2021 | Yes |
Application | adobe | coldfusion | 2021 | Yes |
Application | adobe | coldfusion | 2023 | Yes |
Application | adobe | coldfusion | 2023 | Yes |
Application | adobe | coldfusion | 2023 | Yes |
Application | adobe | coldfusion | 2023 | Yes |
Application | adobe | coldfusion | 2023 | Yes |
Application | adobe | coldfusion | 2023 | Yes |
Application | adobe | coldfusion | 2023 | Yes |
Application | adobe | coldfusion | 2023 | Yes |
Application | adobe | coldfusion | 2023 | Yes |
Application | adobe | coldfusion | 2023 | Yes |
Application | adobe | coldfusion | 2023 | Yes |
Application | adobe | coldfusion | 2023 | Yes |
Application | adobe | coldfusion | 2023 | Yes |
Application | adobe | coldfusion | 2023 | Yes |
Application | adobe | coldfusion | 2023 | Yes |
Application | adobe | coldfusion | 2025 | Yes |
Application | adobe | coldfusion | 2025 | Yes |
Application | adobe | coldfusion | 2025 | Yes |