Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3gxj-2579-vrcc

Опубликовано: 08 апр. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 8.7

Описание

ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to a security feature bypass. An attacker could exploit this vulnerability to access files and directories that are stored outside the intended restricted directory. Exploitation of this issue requires user interaction.

ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to a security feature bypass. An attacker could exploit this vulnerability to access files and directories that are stored outside the intended restricted directory. Exploitation of this issue requires user interaction.

EPSS

Процентиль: 75%
0.00916
Низкий

8.7 High

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 8.7
nvd
10 месяцев назад

ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to a security feature bypass. A high privileged attacker could exploit this vulnerability to bypass security protections and gain unauthorized write and delete access. Exploitation of this issue does not require user interaction and scope is changed.

CVSS3: 8.7
fstec
10 месяцев назад

Уязвимость программной платформы ColdFusion, связанная с неверным ограничением имени пути к каталогу с ограниченным доступом, позволяющая нарушителю обойти ограничения безопасности

EPSS

Процентиль: 75%
0.00916
Низкий

8.7 High

CVSS3

Дефекты

CWE-22