ColdFusion | Incorrect Authorization (CWE-863)

Stammdaten

Kritikalität
CVE ID
CVE-2025-43561
Aktualisiert am:
2025-05-15T04:01:44.542Z
Veröffentlicht am:
2025-05-13T20:49:25.787Z
 

Betroffene Produkte

Hersteller:
Adobe
Produkt(e):
ColdFusion
Betroffene Version:
0
 

Beschreibung

ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. A high-privileged attacker could leverage this vulnerability to bypass authentication mechanisms and execute code. Exploitation of this issue does not require user interaction and scope is changed.
 

Referenzen

 

NIST-Link:


Copyright © 2024 · All Rights Reserved · https://www.tecxero.com | Impressum