Impact
The flaw is a classic cross‑site scripting weakness (CWE‑79) that can allow an attacker to inject arbitrary JavaScript which, when executed in a victim’s browser, can lead to code execution under the victim’s user context. The description explicitly states that the effect is “arbitrary code execution in the context of the current user.” Because the vulnerability is limited to the administrative network zone, the likelihood of exploitation in a public‑facing environment is low. The likely attack vector is inferred to be a social‑engineering scenario where an administrative user is tricked into opening a malicious file, after which the injected script runs with the user’s privileges.
Affected Systems
Adobe ColdFusion 2023 and Adobe ColdFusion 2025 are affected. All build and update versions enumerated in the CPE list (2023 update1–update22, 2025 update1–update9, plus base releases) are vulnerable until a vendor fix is applied.
Risk and Exploitability
The CVSS score of 8.8 rates the issue as high severity, and the EPSS score of 7 % indicates a moderate likelihood of exploitation. The vulnerability is not in the CISA KEV catalog, suggesting it is not yet widely exploited. Because the flaw requires user interaction—an administrative user must open a crafted file in the default admin network zone—attacks are moderately difficult, but the impact of successful exploitation is full code execution under the victim’s privileges.
OpenCVE Enrichment