Stored Cross-Site Scripting Vulnerability in Adobe ColdFusion
CVE-2025-49541

4.3MEDIUM

Key Information:

Vendor

Adobe

Vendor
CVE Published:
8 July 2025

What is CVE-2025-49541?

Adobe ColdFusion is susceptible to a stored Cross-Site Scripting (XSS) vulnerability in versions 2025.2, 2023.14, and 2021.20, along with earlier releases. This vulnerability allows high-privileged attackers to inject malicious JavaScript scripts into vulnerable form fields. When a user accesses the affected page, the injected scripts could execute in the user's browser, potentially compromising user data and allowing unauthorized actions. The vulnerability is limited to internal IP address access.

Affected Version(s)

ColdFusion 0 <= 2021.20

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-49541 : Stored Cross-Site Scripting Vulnerability in Adobe ColdFusion