PT-2018-3484 · Adobe · Coldfusion
Pete Freitag
·
Published
2018-09-11
·
Updated
2025-10-23
·
CVE-2018-15961
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
Adobe ColdFusion versions July 12 release (2018.0.0.310739) through Update 6
Adobe ColdFusion versions July 12 release (2018.0.0.310739) through Update 14
Description:
The issue is related to an unrestricted file upload vulnerability in the ColdFusion interpreter. This vulnerability could allow a remote attacker to execute arbitrary code. Successful exploitation of this vulnerability may lead to arbitrary code execution.
Recommendations:
For Adobe ColdFusion versions July 12 release (2018.0.0.310739) through Update 6, update to a version later than Update 6 to resolve the issue.
For Adobe ColdFusion versions July 12 release (2018.0.0.310739) through Update 14, update to a version later than Update 14 to resolve the issue.
As a temporary workaround, consider restricting file uploads to minimize the risk of exploitation.
Exploit
Fix
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Coldfusion