Stored Cross-Site Scripting Vulnerability in Adobe ColdFusion
CVE-2025-49540
4.3MEDIUM
What is CVE-2025-49540?
Adobe ColdFusion versions 2025.2, 2023.14, 2021.20, and earlier releases are susceptible to a stored Cross-Site Scripting (XSS) vulnerability. A malicious actor with elevated privileges can exploit this weakness to inject harmful scripts into form fields. If a victim interacts with the compromised form field and accesses the corresponding page, the injected malicious JavaScript can be executed in their browser. It is important to note that this issue is limited to internal IP addresses, which confines the potential attack surface.
Affected Version(s)
ColdFusion 0 <= 2021.20