Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7fxq-8gr3-9c2f

Опубликовано: 08 июл. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by a Use of Hard-coded Credentials vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain unauthorized access to sensitive systems or data. Exploitation of this issue does not require user interaction. The vulnerable component is restricted to internal IP addresses.

ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by a Use of Hard-coded Credentials vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain unauthorized access to sensitive systems or data. Exploitation of this issue does not require user interaction. The vulnerable component is restricted to internal IP addresses.

EPSS

Процентиль: 13%
0.00042
Низкий

8.8 High

CVSS3

Дефекты

CWE-798

Связанные уязвимости

CVSS3: 8.8
nvd
7 месяцев назад

ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by a Use of Hard-coded Credentials vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain unauthorized access to sensitive systems or data. Exploitation of this issue does not require user interaction. The vulnerable component is restricted to internal IP addresses.

CVSS3: 8.8
fstec
7 месяцев назад

Уязвимость программной платформы ColdFusion, связанная с использованием жестко закодированных учетных данных, позволяющая нарушителю повысить свои привилегии

EPSS

Процентиль: 13%
0.00042
Низкий

8.8 High

CVSS3

Дефекты

CWE-798