Логотип exploitDog
bind:CVE-2025-43561
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-43561

Количество 3

Количество 3

nvd логотип

CVE-2025-43561

9 месяцев назад

ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. A high-privileged attacker could leverage this vulnerability to bypass authentication mechanisms and execute code. Exploitation of this issue does not require user interaction and scope is changed.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-r75c-5vvp-mrg6

9 месяцев назад

ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. A high-privileged attacker could leverage this vulnerability to bypass authentication mechanisms and execute code. Exploitation of this issue does not require user interaction and scope is changed.

CVSS3: 9.1
EPSS: Низкий
fstec логотип

BDU:2025-05503

9 месяцев назад

Уязвимость программной платформы ColdFusion, связанная с недостатками механизма авторизации, позволяющая нарушителю обойти существующие ограничения безопасности и выполнить произвольный код

CVSS3: 9.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-43561

ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. A high-privileged attacker could leverage this vulnerability to bypass authentication mechanisms and execute code. Exploitation of this issue does not require user interaction and scope is changed.

CVSS3: 9.1
1%
Низкий
9 месяцев назад
github логотип
GHSA-r75c-5vvp-mrg6

ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. A high-privileged attacker could leverage this vulnerability to bypass authentication mechanisms and execute code. Exploitation of this issue does not require user interaction and scope is changed.

CVSS3: 9.1
1%
Низкий
9 месяцев назад
fstec логотип
BDU:2025-05503

Уязвимость программной платформы ColdFusion, связанная с недостатками механизма авторизации, позволяющая нарушителю обойти существующие ограничения безопасности и выполнить произвольный код

CVSS3: 9.1
1%
Низкий
9 месяцев назад

Уязвимостей на страницу