Логотип exploitDog
bind:CVE-2025-30281
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-30281

Количество 3

Количество 3

nvd логотип

CVE-2025-30281

10 месяцев назад

ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary code execution. A high-privileged attacker could leverage this vulnerability to access or modify sensitive data without proper authorization. Exploitation of this issue does not require user interaction, and scope is changed.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-r3m2-p27f-8635

10 месяцев назад

ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary file system read. An attacker could leverage this vulnerability to access or modify sensitive data without proper authorization. Exploitation of this issue does not require user interaction.

CVSS3: 9.1
EPSS: Низкий
fstec логотип

BDU:2025-04064

10 месяцев назад

Уязвимость программной платформы ColdFusion, связанная с ошибками разграничения доступа, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

CVSS3: 9.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-30281

ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary code execution. A high-privileged attacker could leverage this vulnerability to access or modify sensitive data without proper authorization. Exploitation of this issue does not require user interaction, and scope is changed.

CVSS3: 9.1
8%
Низкий
10 месяцев назад
github логотип
GHSA-r3m2-p27f-8635

ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary file system read. An attacker could leverage this vulnerability to access or modify sensitive data without proper authorization. Exploitation of this issue does not require user interaction.

CVSS3: 9.1
8%
Низкий
10 месяцев назад
fstec логотип
BDU:2025-04064

Уязвимость программной платформы ColdFusion, связанная с ошибками разграничения доступа, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

CVSS3: 9.1
8%
Низкий
10 месяцев назад

Уязвимостей на страницу