Логотип exploitDog
bind:CVE-2025-43565
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-43565

Количество 3

Количество 3

nvd логотип

CVE-2025-43565

9 месяцев назад

ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Incorrect Authorization vulnerability that could lead to arbitrary code execution in the context of the current user. A high-privileged attacker could leverage this vulnerability to bypass security protections and execute code. Exploitation of this issue requires user interaction and scope is changed.

CVSS3: 8.4
EPSS: Низкий
github логотип

GHSA-hf4x-2pvm-qxvv

9 месяцев назад

ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Incorrect Authorization vulnerability that could lead to arbitrary code execution in the context of the current user. A high-privileged attacker could leverage this vulnerability to bypass security protections and execute code. Exploitation of this issue requires user interaction and scope is changed.

CVSS3: 8.4
EPSS: Низкий
fstec логотип

BDU:2025-05507

9 месяцев назад

Уязвимость программной платформы ColdFusion, связанная с недостатками механизма авторизации, позволяющая нарушителю обойти существующие ограничения безопасности и выполнить произвольный код

CVSS3: 8.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-43565

ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Incorrect Authorization vulnerability that could lead to arbitrary code execution in the context of the current user. A high-privileged attacker could leverage this vulnerability to bypass security protections and execute code. Exploitation of this issue requires user interaction and scope is changed.

CVSS3: 8.4
1%
Низкий
9 месяцев назад
github логотип
GHSA-hf4x-2pvm-qxvv

ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Incorrect Authorization vulnerability that could lead to arbitrary code execution in the context of the current user. A high-privileged attacker could leverage this vulnerability to bypass security protections and execute code. Exploitation of this issue requires user interaction and scope is changed.

CVSS3: 8.4
1%
Низкий
9 месяцев назад
fstec логотип
BDU:2025-05507

Уязвимость программной платформы ColdFusion, связанная с недостатками механизма авторизации, позволяющая нарушителю обойти существующие ограничения безопасности и выполнить произвольный код

CVSS3: 8.4
1%
Низкий
9 месяцев назад

Уязвимостей на страницу