ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution. Exploitation of this issue does not require user interaction, but admin panel privileges are required, and scope is changed.
References
| Link | Resource |
|---|---|
| https://helpx.adobe.com/security/products/coldfusion/apsb25-15.html | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2025-04-08 20:15
Updated : 2025-04-21 18:40
NVD link : CVE-2025-24446
Mitre link : CVE-2025-24446
CVE.ORG link : CVE-2025-24446
JSON object : View
Products Affected
adobe
- coldfusion
CWE
