Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jprg-rppq-7hjg

Опубликовано: 09 сент. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 9

Описание

ColdFusion versions 2025.3, 2023.15, 2021.21 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary code execution by an attacker. Scope is changed.

ColdFusion versions 2025.3, 2023.15, 2021.21 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary code execution by an attacker. Scope is changed.

EPSS

Процентиль: 82%
0.01784
Низкий

9 Critical

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 10
nvd
5 месяцев назад

ColdFusion versions 2025.3, 2023.15, 2021.21 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary code execution by an attacker. The victim must have optional configurations enabled. Scope is changed.

CVSS3: 9
fstec
5 месяцев назад

Уязвимость программной платформы ColdFusion, связанная с неверным ограничением имени пути к каталогу с ограниченным доступом, позволяющая нарушителю записывать произвольные файлы

EPSS

Процентиль: 82%
0.01784
Низкий

9 Critical

CVSS3

Дефекты

CWE-22