vendor:
ColdFusion
by:
Youssef Muhammad
8.1
CVSS
CRITICAL
Arbitrary File Read
22
CWE
Product Name: ColdFusion
Affected Version From: Adobe ColdFusion versions 2018,15
Affected Version To: Adobe ColdFusion versions 2021,5
Patch Exists: NO
Related CWE: CVE-2023-26360
CPE: a:adobe:coldfusion
Platforms Tested: Windows, Linux
2023
Arbitrary File Read Exploit for CVE-2023-26360
The exploit allows an attacker to read arbitrary files on a target system. The vulnerability affects Adobe ColdFusion versions 2018,15 and earlier, as well as 2021,5 and earlier. By exploiting this vulnerability, an attacker can gain unauthorized access to sensitive files on the target system. This exploit is identified by CVE-2023-26360.
Mitigation:
To mitigate this vulnerability, it is recommended to apply the necessary security patches provided by Adobe for the affected versions. Additionally, restrict network access to the ColdFusion service to limit exposure.