Cross-Site Scripting Flaw in Adobe ColdFusion Products
CVE-2018-4941
6.1MEDIUM
Key Information:
- Vendor
- Adobe
- Vendor
- CVE Published:
- 19 May 2018
Summary
Adobe ColdFusion versions prior to Update 5 and ColdFusion 11 versions prior to Update 13 are susceptible to a Cross-Site Scripting vulnerability. This flaw may allow attackers to inject malicious scripts into web pages viewed by other users, potentially leading to the disclosure of sensitive information. Proper mitigations should be employed to secure affected systems and safeguard critical data.
Affected Version(s)
Adobe ColdFusion ColdFusion Update 5 and earlier , ColdFusion 11 Update 13 and earlier Adobe ColdFusion ColdFusion Update 5 and earlier versions, ColdFusion 11 Update 13 and earlier versions
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved