vendor:
                    ColdFusion
                by:
                    Youssef Muhammad
                8.1
                        CVSS
                    CRITICAL
                    Arbitrary File Read
                    22
                        CWE
                    Product Name: ColdFusion
                    Affected Version From:  Adobe ColdFusion versions 2018,15
                    Affected Version To:  Adobe ColdFusion versions 2021,5
                    Patch Exists: NO
                    Related CWE: CVE-2023-26360
                    CPE:  a:adobe:coldfusion
                    Platforms Tested:  Windows, Linux
                    2023
                    Arbitrary File Read Exploit for CVE-2023-26360
The exploit allows an attacker to read arbitrary files on a target system. The vulnerability affects Adobe ColdFusion versions 2018,15 and earlier, as well as 2021,5 and earlier. By exploiting this vulnerability, an attacker can gain unauthorized access to sensitive files on the target system. This exploit is identified by CVE-2023-26360.
Mitigation:
					To mitigate this vulnerability, it is recommended to apply the necessary security patches provided by Adobe for the affected versions. Additionally, restrict network access to the ColdFusion service to limit exposure.