Impact
ColdFusion is vulnerable to a Server-Side Request Forgery that allows a low-privileged attacker to bypass security mechanisms and read data that should be protected. The flaw can be triggered without user interaction and changes the security scope of the application, potentially exposing internal resources to the attacker.
Affected Systems
Adobe ColdFusion versions 2023 and 2025 are affected. No specific patch versions are listed, so any release prior to the official fix should be considered vulnerable.
Risk and Exploitability
The CVSS score of 7.7 reflects a moderate to high severity, while an EPSS score of 11% indicates a relatively low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog, but it can be leveraged directly from the exposed service, suggesting that the attack vector is remote exploitation of the ColdFusion instance.
OpenCVE Enrichment