Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. An unauthenticated attacker could leverage this vulnerability to impact a minor integrity feature. Exploitation of this issue does require user interaction.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 11 Oct 2024 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 16 Sep 2024 13:15:00 +0000

Type Values Removed Values Added
Title Reflected HTML Injection in coldfusion.servicelayer.ServicelayerExceptions exceptions ColdFusion | Improper Input Validation (CWE-20)

cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2024-10-11T15:59:51.033Z

Reserved: 2023-09-28T16:25:40.452Z

Link: CVE-2023-44355

cve-icon Vulnrichment

Updated: 2024-08-02T20:07:32.175Z

cve-icon NVD

Status : Modified

Published: 2023-11-17T14:15:22.083

Modified: 2024-11-21T08:25:44.550

Link: CVE-2023-44355

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.