Impact
The vulnerability is a reflected Cross‑Site Scripting flaw triggered when a user accesses a specially crafted URL that contains malicious JavaScript. Because the input is reflected back into the page without proper encoding, the script runs in the victim’s browser context. This can lead to session hijacking, credential theft, or defacement. The weakness corresponds to CWE‑79, and the NIST scores list a CVSS of 6.1, indicating moderate severity. The flaw changes the security scope, meaning it can impact multiple users rather than a single session.
Affected Systems
Adobe ColdFusion products 2023 and 2025 are affected. The flaw is present in all builds of these releases, as documented by Adobe in the security advisory.
Risk and Exploitability
The attack vector is inferred to be remote via a crafted URL that a victim is persuaded to visit. An attacker preparing a malicious link can embed JavaScript that executes in the victim’s browser. Because the vulnerability changes scope, a successful exploitation could affect many users of the application. The CVSS score of 6.1 reflects a moderate risk, and the EPSS score is unavailable, but the lack of a KEV listing suggests no widespread exploitation has been reported yet.
OpenCVE Enrichment