Executive brief
Adobe ColdFusion contains an improper access control vulnerability that allows for arbitrary file system read and modification. Exploitation requires the admin panel to be exposed to the internet but does not require user interaction.
Affected products
- Adobe ColdFusion 2023.6, 2021.12 and earlier
Timeline
- 2024-03-18: disclosed: New CVE received from Adobe Systems Incorporated
- 2024-12-16: kev added: Added to CISA Known Exploited Vulnerabilities Catalog