Stored XSS Vulnerability in ColdFusion by Adobe
CVE-2025-49543

4.3MEDIUM

Key Information:

Vendor

Adobe

Vendor
CVE Published:
8 July 2025

What is CVE-2025-49543?

ColdFusion versions 2025.2, 2023.14, and 2021.20, along with earlier versions, are at risk due to a stored Cross-Site Scripting (XSS) vulnerability. This issue allows high-privileged attackers to inject malicious scripts into vulnerable form fields. When users access web pages containing these compromised fields, the injected JavaScript can execute in their browsers, posing a significant security risk. Importantly, the vulnerable component is only accessible via internal IP addresses, which may limit exposure but still necessitates immediate attention.

Affected Version(s)

ColdFusion 0 <= 2021.20

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.