Cross-Site Scripting Flaw in Adobe ColdFusion Products
CVE-2018-4941

6.1MEDIUM

Summary

Adobe ColdFusion versions prior to Update 5 and ColdFusion 11 versions prior to Update 13 are susceptible to a Cross-Site Scripting vulnerability. This flaw may allow attackers to inject malicious scripts into web pages viewed by other users, potentially leading to the disclosure of sensitive information. Proper mitigations should be employed to secure affected systems and safeguard critical data.

Affected Version(s)

Adobe ColdFusion ColdFusion Update 5 and earlier , ColdFusion 11 Update 13 and earlier Adobe ColdFusion ColdFusion Update 5 and earlier versions, ColdFusion 11 Update 13 and earlier versions

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.