PT-2018-3484 · Adobe · Coldfusion

Pete Freitag

·

Published

2018-09-11

·

Updated

2025-10-23

·

CVE-2018-15961

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Adobe ColdFusion versions July 12 release (2018.0.0.310739) through Update 6 Adobe ColdFusion versions July 12 release (2018.0.0.310739) through Update 14
Description: The issue is related to an unrestricted file upload vulnerability in the ColdFusion interpreter. This vulnerability could allow a remote attacker to execute arbitrary code. Successful exploitation of this vulnerability may lead to arbitrary code execution.
Recommendations: For Adobe ColdFusion versions July 12 release (2018.0.0.310739) through Update 6, update to a version later than Update 6 to resolve the issue. For Adobe ColdFusion versions July 12 release (2018.0.0.310739) through Update 14, update to a version later than Update 14 to resolve the issue. As a temporary workaround, consider restricting file uploads to minimize the risk of exploitation.

Exploit

Fix

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-02111
CVE-2018-15961

Affected Products

Coldfusion