PT-2019-5911 · Adobe · Coldfusion
Published
2019-06-12
·
Updated
2020-09-04
·
CVE-2019-7838
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
ColdFusion versions Update 3 and earlier
ColdFusion versions Update 10 and earlier
ColdFusion versions Update 18 and earlier
Description
The issue is related to a file extension blacklist bypass vulnerability, which could allow a remote attacker to execute arbitrary code by exploiting the unlimited upload of dangerous file types. Successful exploitation of this issue may lead to arbitrary code execution.
Recommendations
For ColdFusion versions Update 3 and earlier, update to a version later than Update 3 to resolve the issue.
For ColdFusion versions Update 10 and earlier, update to a version later than Update 10 to resolve the issue.
For ColdFusion versions Update 18 and earlier, update to a version later than Update 18 to resolve the issue.
Fix
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Coldfusion