PT-2015-2756 · Adobe · Coldfusion

Published

2015-11-18

·

Updated

2020-09-04

·

CVE-2015-8052

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Adobe ColdFusion versions 10 before Update 18 Adobe ColdFusion versions 11 before Update 7
Description The issue is related to a cross-site scripting (XSS) vulnerability that allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. This occurs due to a lack of protection measures for the web page structure, which can be exploited by a remote attacker to inject malicious code.
Recommendations For Adobe ColdFusion version 10, apply Update 18 to resolve the issue. For Adobe ColdFusion version 11, apply Update 7 to resolve the issue.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-12121
CVE-2015-8052
MGASA-2015-0468

Affected Products

Coldfusion