Adobe ColdFusion
cpe:2.3:a:adobe:coldfusion:*:*:*:*:*:*:*
- <= 2025.1
- <= 2023.13
- <= 2021.19
An improper access control vulnerability has been identified in Adobe ColdFusion versions 2025.1, 2023.13, and 2021.19 and earlier. This vulnerability could allow an attacker to read arbitrary files from the file system, potentially leading to unauthorized access or modification of sensitive data. The exploitation of this vulnerability does not require any user interaction.
Exploitation of this vulnerability could result in unauthorized access to or modification of sensitive data by allowing attackers to read arbitrary files from the file system.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.