Impact
A reflected cross‑site scripting vulnerability in Adobe ColdFusion allows attackers to inject malicious scripts into web pages displayed to users, potentially granting elevated access or control over the victim’s account or session. The flaw is confined to an administrative network zone by default and requires user interaction: a victim must open a malicious file. The change in scope indicates escalation potential.
Affected Systems
Adobe ColdFusion 2023 and Adobe ColdFusion 2025 are affected. The vulnerability applies to all listed releases, including each available update version, and no newer releases are mentioned, so any installation of the described versions is vulnerable.
Risk and Exploitability
The CVSS score of 8.5 indicates high severity, while the EPSS score of <1% suggests a low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog, indicating no known public exploitation campaigns. The vulnerability requires user interaction, implying that an attacker must supply a malicious file or link to a victim. Based on this requirement, the likely attack vector involves user interaction such as clicking a link or opening a file, typically achieved through social engineering or phishing. The component is confined to an administrative network zone by default, limiting exposure to environments that expose the vulnerable component.
OpenCVE Enrichment