Impact
An Improper Encoding or Escaping of Output vulnerability causes a security feature bypass. Based on the description, it is inferred that an attacker with low privileges could inject content that is not correctly sanitized, enabling limited unauthorized write access. The attack can disrupt availability at a limited level. No user interaction is required to exploit the flaw.
Affected Systems
Adobe ColdFusion 2023 and Adobe ColdFusion 2025 are affected. The affected versions include ColdFusion 2023 from update1 through update20 (plus the base 2023 release) and ColdFusion 2025 from update1 through update9 (plus the base 2025 release).
Risk and Exploitability
Based on the description, it is inferred that the attack vector is likely through web interfaces where crafted input can be supplied to the ColdFusion application without requiring user interaction. The CVSS score of 5.4 indicates moderate severity, while the EPSS score of 15% suggests a moderate likelihood of exploitation. The vulnerability is not listed in CISA’s KEV catalog.
OpenCVE Enrichment