Impact
ColdFusion is affected by an Improper Neutralization of Special Elements used in an SQL Command, leading to SQL Injection that can be used to execute arbitrary code in the context of the current user. The vulnerability allows an attacker with high privileges to run code without requiring any user interaction and changes the affected scope.
Affected Systems
Adobe ColdFusion 2023 and Adobe ColdFusion 2025 are affected. No specific version numbers are listed, so all releases within those product lines are potentially impacted until patches are applied.
Risk and Exploitability
The CVSS base score of 9.1 classifies this flaw as Critical, and the vulnerability can be exploited remotely, likely via a network‑facing HTTP endpoint, although the exact attack vector is inferred. The EPSS score is 1% and the flaw is not listed in CISA KEV, but the scope change and lack of requirement for user interaction mean that attackers who have access to high‑privilege users or internal networks can fully compromise a system. Immediate remediation is recommended to mitigate the high risk.
OpenCVE Enrichment