Impact
An Improper Encoding or Escaping of Output vulnerability causes a security feature bypass. Based on the description, it is inferred that an attacker with low privileges could inject content that is not correctly sanitized, enabling limited unauthorized write access. The attack can disrupt availability at a limited level. No user interaction is required to exploit the flaw.
Affected Systems
Adobe ColdFusion 2023 and Adobe ColdFusion 2025 are affected. Specific version information is not provided.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate severity, while the EPSS score of 14% suggests a moderate likelihood of exploitation. The vulnerability is not listed in CISA’s KEV catalog. Although no explicit attack vector is disclosed, the flaw can be triggered by carefully crafted input to the ColdFusion application, likely through its web interfaces, without needing user interaction.
OpenCVE Enrichment