Impact
ColdFusion contains a CWE-89 vulnerability, Improper Neutralization of Special Elements used in an SQL Command, that permits an attacker to inject malicious SQL statements. The injection flaw can result in arbitrary code execution in the context of the current user. Because the vulnerability changes the system scope, it may allow an attacker with high privileges to execute code with higher privileges on the underlying system.
Affected Systems
Adobe ColdFusion 2023 and Adobe ColdFusion 2025 are affected; all releases within those major versions should be considered vulnerable until the advisory specifies otherwise.
Risk and Exploitability
The CVSS score of 9.1 classifies this vulnerability as high severity. The EPSS score of 1% indicates a low probability of exploitation at this time, yet the flaw remains a significant risk. It is not listed in the CISA KEV catalog. Based on the description, it is inferred that the likely attack vector is automated web requests that include untrusted input, and the attack does not require user interaction. Because the vulnerability changes scope, executing arbitrary code can affect the application or the underlying system.
OpenCVE Enrichment