vendor:
Adobe ColdFusion
by:
Youssef Muhammad
8.1
CVSS
CRITICAL
Arbitrary File Read
22
CWE
Product Name: Adobe ColdFusion
Affected Version From: Adobe ColdFusion versions 2018,15
Affected Version To: Adobe ColdFusion versions 2021,5
Patch Exists: YES
Related CWE: CVE-2023-26360
CPE: a:adobe:coldfusion
Platforms Tested: Windows, Linux
2023
File Read Arbitrary Exploit for CVE-2023-26360
An exploit for Adobe ColdFusion versions 2018,15 and earlier, and 2021,5 and earlier allows an attacker to read arbitrary files due to improper input validation. This vulnerability is identified as CVE-2023-26360.
Mitigation:
To mitigate this vulnerability, it is recommended to restrict access to sensitive files, apply security patches provided by the vendor, and update to the latest version of Adobe ColdFusion.