Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jprg-rppq-7hjg

Опубликовано: 09 сент. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 9

Описание

ColdFusion versions 2025.3, 2023.15, 2021.21 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary code execution by an attacker. Scope is changed.

ColdFusion versions 2025.3, 2023.15, 2021.21 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary code execution by an attacker. Scope is changed.

EPSS

Процентиль: 97%
0.19934
Средний

9 Critical

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 10
nvd
12 месяцев назад

ColdFusion versions 2025.3, 2023.15, 2021.21 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary code execution by an attacker. The victim must have optional configurations enabled. Scope is changed.

CVSS3: 9
fstec
12 месяцев назад

Уязвимость программной платформы ColdFusion, связанная с неверным ограничением имени пути к каталогу с ограниченным доступом, позволяющая нарушителю записывать произвольные файлы

EPSS

Процентиль: 97%
0.19934
Средний

9 Critical

CVSS3

Дефекты

CWE-22