Executive brief
Adobe ColdFusion contains an unrestricted file upload vulnerability (CWE-434) in multiple versions. An unauthenticated remote attacker can exploit this to upload malicious files, potentially leading to arbitrary code execution on the server.
Affected products
- Adobe ColdFusion 2018.0.0.310739 (July 12 release) and earlier; 2016 Update 14 and earlier; 11 Update 6 and earlier
Timeline
- 2018-09-11: advisory: Adobe released security bulletin APSB18-33
- 2021-11-03: kev added: CISA added this vulnerability to the Known Exploited Vulnerabilities (KEV) catalog.
- 2021-11-03: disclosed: NVD publication date.