Executive brief
Adobe ColdFusion is a server-side web application platform used to build dynamic websites and applications. A stored cross-site scripting vulnerability in form field handling allows attackers with low privileges to inject malicious scripts that execute in other users' browsers, potentially leading to session hijacking, credential theft, or unauthorized actions performed on behalf of legitimate users.
Technical details
The vulnerability is a stored cross-site scripting (XSS) flaw in ColdFusion's form field processing. An attacker with low privileges can inject malicious JavaScript into vulnerable form fields, and the payload persists in the application (stored). When other users browse to pages containing the compromised field, the malicious script executes in their browsers with the same privileges as the victim user. The scope is changed, meaning the vulnerability affects resources beyond the vulnerable component itself. No authentication bypass is required—a low-privileged account is sufficient to inject the payload.
Affected products
- Adobe ColdFusion
Timeline
- 2026-08-11: disclosed