Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qj34-w7fp-qg2w

Опубликовано: 08 апр. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 6.8

Описание

ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Input Validation vulnerability that could result in a security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized access. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Input Validation vulnerability that could result in a security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized access. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

EPSS

Процентиль: 78%
0.01172
Низкий

6.8 Medium

CVSS3

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 6.8
nvd
10 месяцев назад

ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Input Validation vulnerability that could result in a security feature bypass. A high-privileged attacker could leverage this vulnerability to bypass security protections and gain unauthorized write access. Exploitation of this issue does not require user interaction and scope is changed.

CVSS3: 6.8
fstec
10 месяцев назад

Уязвимость программной платформы ColdFusion, связана с недостаточной проверкой входных данных, позволяющая нарушителю обойти существующие ограничения безопасности

EPSS

Процентиль: 78%
0.01172
Низкий

6.8 Medium

CVSS3

Дефекты

CWE-20