Impact
ColdFusion is affected by a reflected Cross‑Site Scripting (XSS) vulnerability that allows an attacker to inject malicious scripts into a web page. The flaw can be exploited when a victim opens a specially crafted file, potentially enabling an attacker to gain elevated access or control over the victim's account or session. The issue is a classic case of CWE‑79 where improperly sanitized input is reflected back to the user, allowing script execution in the victim’s browser.
Affected Systems
The vulnerability affects Adobe ColdFusion 2023 and Adobe ColdFusion 2025. All releases of these product lines prior to the update in the Adobe Security Advisory (APSB26‑119) are susceptible. Users should verify the specific ColdFusion version installed and determine whether the fix has been applied.
Risk and Exploitability
The CVSS score of 8.5 indicates a high severity rating. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog, suggesting no confirmed widescale exploitation yet. The attack requires user interaction to open a malicious file, so it is an interactive exploitation rather than an automated or remote attack. As a reflected XSS, it may allow attackers to steal session cookies or perform actions on behalf of a victim who visits the crafted link.
OpenCVE Enrichment