Improper XML External Entity Reference Vulnerability in Adobe ColdFusion Products
CVE-2025-61823

6.2MEDIUM

Key Information:

Vendor

Adobe

Vendor
CVE Published:
9 December 2025

What is CVE-2025-61823?

Adobe ColdFusion versions 2025.4, 2023.16, and 2021.22 are susceptible to an Improper Restriction of XML External Entity Reference (XXE). This vulnerability enables attackers with high privileges to read arbitrary files from the server's file system, potentially exposing sensitive information. Successful exploitation necessitates specific user interactions, altering the scope of the threat.

Affected Version(s)

ColdFusion 0 <= 2021.22

References

CVSS V3.1

Score:
6.2
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.