ZeroHour

CVE-2025-43565

CVSS 3.1
8.4 high
EPSS
16%p97
Published
()
Modified
Description

ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Incorrect Authorization vulnerability that could lead to arbitrary code execution in the context of the current user. A high-privileged attacker could leverage this vulnerability to bypass security protections and execute code. Exploitation of this issue requires user interaction and scope is changed.

Vendors
adobe
Products
coldfusion
Weakness
CWE-863
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.