Cross-Site Scripting in Adobe ColdFusion by Adobe
CVE-2018-4940

6.1MEDIUM

Summary

Adobe ColdFusion versions Update 5 and earlier, as well as ColdFusion 11 Update 13 and earlier, contain a vulnerability that enables Cross-Site Scripting (XSS) attacks. This security flaw can be exploited by malicious actors to potentially disclose sensitive information from affected systems. It is critical for users of the impacted versions to evaluate their environment and apply necessary patches to prevent exploitation.

Affected Version(s)

Adobe ColdFusion ColdFusion Update 5 and earlier , ColdFusion 11 Update 13 and earlier Adobe ColdFusion ColdFusion Update 5 and earlier versions, ColdFusion 11 Update 13 and earlier versions

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.