vendor:
ColdFusion
by:
Youssef Muhammad
8.1
CVSS
CRITICAL
Arbitrary File Read
22
CWE
Product Name: ColdFusion
Affected Version From: Adobe ColdFusion versions 2018,15
Affected Version To: Adobe ColdFusion 2021,5
Patch Exists: NO
Related CWE: CVE-2023-26360
CPE: a:adobe:coldfusion
Platforms Tested: Windows, Linux
2023
File Read Arbitrary Exploit for CVE-2023-26360
The exploit allows an attacker to read arbitrary files on the target system. This affects Adobe ColdFusion versions 2018,15 and earlier, as well as 2021,5 and earlier. It exploits CVE-2023-26360.
Mitigation:
To mitigate this vulnerability, users should update to the latest patched version of Adobe ColdFusion. Additionally, restrict access to sensitive files and directories.