Логотип exploitDog
bind:CVE-2025-30294
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-30294

Количество 3

Количество 3

nvd логотип

CVE-2025-30294

10 месяцев назад

ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Input Validation vulnerability that could result in a security feature bypass. A high-privileged attacker could leverage this vulnerability to bypass security protections and gain unauthorized read access. Exploitation of this issue does not require user interaction and scope is changed.

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-rv7x-66xx-8rvv

10 месяцев назад

ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Input Validation vulnerability that could result in a security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized access. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 6.5
EPSS: Низкий
fstec логотип

BDU:2025-04789

10 месяцев назад

Уязвимость программной платформы ColdFusion, связана с недостаточной проверкой входных данных, позволяющая нарушителю обойти существующие ограничения безопасности

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-30294

ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Input Validation vulnerability that could result in a security feature bypass. A high-privileged attacker could leverage this vulnerability to bypass security protections and gain unauthorized read access. Exploitation of this issue does not require user interaction and scope is changed.

CVSS3: 6.8
2%
Низкий
10 месяцев назад
github логотип
GHSA-rv7x-66xx-8rvv

ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Input Validation vulnerability that could result in a security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized access. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 6.5
2%
Низкий
10 месяцев назад
fstec логотип
BDU:2025-04789

Уязвимость программной платформы ColdFusion, связана с недостаточной проверкой входных данных, позволяющая нарушителю обойти существующие ограничения безопасности

CVSS3: 6.5
2%
Низкий
10 месяцев назад

Уязвимостей на страницу