PT-2019-5911 · Adobe · Coldfusion

Published

2019-06-12

·

Updated

2020-09-04

·

CVE-2019-7838

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ColdFusion versions Update 3 and earlier ColdFusion versions Update 10 and earlier ColdFusion versions Update 18 and earlier
Description The issue is related to a file extension blacklist bypass vulnerability, which could allow a remote attacker to execute arbitrary code by exploiting the unlimited upload of dangerous file types. Successful exploitation of this issue may lead to arbitrary code execution.
Recommendations For ColdFusion versions Update 3 and earlier, update to a version later than Update 3 to resolve the issue. For ColdFusion versions Update 10 and earlier, update to a version later than Update 10 to resolve the issue. For ColdFusion versions Update 18 and earlier, update to a version later than Update 18 to resolve the issue.

Fix

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-03785
CVE-2019-7838

Affected Products

Coldfusion