Логотип exploitDog
bind:CVE-2025-30288
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-30288

Количество 3

Количество 3

nvd логотип

CVE-2025-30288

10 месяцев назад

ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. A low privileged attacker with local access could leverage this vulnerability to bypass security protections and execute code. Exploitation of this issue requires user interaction in that a victim must be coerced into performing actions within the application and scope is changed.

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-j72q-qc2x-rq8g

10 месяцев назад

ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized access. Exploitation of this issue does not require user interaction.

CVSS3: 7.8
EPSS: Низкий
fstec логотип

BDU:2025-04073

10 месяцев назад

Уязвимость программной платформы ColdFusion, связанная с ошибками разграничения доступа, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

CVSS3: 7.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-30288

ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. A low privileged attacker with local access could leverage this vulnerability to bypass security protections and execute code. Exploitation of this issue requires user interaction in that a victim must be coerced into performing actions within the application and scope is changed.

CVSS3: 8.2
0%
Низкий
10 месяцев назад
github логотип
GHSA-j72q-qc2x-rq8g

ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized access. Exploitation of this issue does not require user interaction.

CVSS3: 7.8
0%
Низкий
10 месяцев назад
fstec логотип
BDU:2025-04073

Уязвимость программной платформы ColdFusion, связанная с ошибками разграничения доступа, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

CVSS3: 7.8
0%
Низкий
10 месяцев назад

Уязвимостей на страницу