Improper Input Validation in ColdFusion by Adobe
CVE-2025-61822
6.2MEDIUM
What is CVE-2025-61822?
Adobe ColdFusion versions 2025.4, 2023.16, and 2021.22 and earlier contain an improper input validation flaw that allows an attacker to exploit this vulnerability to write malicious files to any arbitrary location in the file system. This can lead to significant security risks, as such exploitation does not necessitate any user interaction, thereby broadening the scope of potential attacks against systems running vulnerable versions of ColdFusion.
Affected Version(s)
ColdFusion 0 <= 2021.22