Логотип exploitDog
bind: "CVE-2025-61810"
Консоль
Логотип exploitDog

exploitDog

bind: "CVE-2025-61810"

Количество 3

Количество 3

nvd логотип

CVE-2025-61810

9 дней назад

ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. A high privileged attacker could exploit this vulnerability by providing maliciously crafted serialized data to the application. Exploitation of this issue requires user interaction and scope is changed.

CVSS3: 8.4
EPSS: Низкий
github логотип

GHSA-cjmh-96m9-g6qr

9 дней назад

ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. A high privileged attacker could exploit this vulnerability by providing maliciously crafted serialized data to the application. Exploitation of this issue requires user interaction and scope is changed.

CVSS3: 8.4
EPSS: Низкий
fstec логотип

BDU:2025-15512

10 дней назад

Уязвимость программной платформы ColdFusion, связанная с недостатками механизма десериализации, позволяющая нарушителю выполнить произвольный код

CVSS3: 8.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-61810

ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. A high privileged attacker could exploit this vulnerability by providing maliciously crafted serialized data to the application. Exploitation of this issue requires user interaction and scope is changed.

CVSS3: 8.4
4%
Низкий
9 дней назад
github логотип
GHSA-cjmh-96m9-g6qr

ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. A high privileged attacker could exploit this vulnerability by providing maliciously crafted serialized data to the application. Exploitation of this issue requires user interaction and scope is changed.

CVSS3: 8.4
4%
Низкий
9 дней назад
fstec логотип
BDU:2025-15512

Уязвимость программной платформы ColdFusion, связанная с недостатками механизма десериализации, позволяющая нарушителю выполнить произвольный код

CVSS3: 8.4
4%
Низкий
10 дней назад

Уязвимостей на страницу