Improper Restriction of XML External Entity Reference in Adobe ColdFusion
CVE-2025-61821
6.8MEDIUM
What is CVE-2025-61821?
Adobe ColdFusion versions 2025.4, 2023.16, 2021.22, and earlier versions are susceptible to an Improper Restriction of XML External Entity Reference vulnerability. This flaw could enable an attacker to exploit the system, potentially leading to unauthorized access to sensitive files and data stored on the server. The exploitation of this vulnerability does not require any user interaction, making it a significant risk for server integrity and data confidentiality.
Affected Version(s)
ColdFusion 0 <= 2021.22