PT-2025-33671 · Adobe · Coldfusion

Published

2025-08-18

·

Updated

2025-10-01

·

CVE-2025-54234

CVSS v3.1

2.7

Low

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions: ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier
Description: ColdFusion is susceptible to a Server-Side Request Forgery (SSRF) issue that may allow limited file system read access. A high-privilege authenticated attacker can exploit this by injecting arbitrary URLs, forcing the application to make requests to those URLs. This does not require any user interaction.
Recommendations: Update ColdFusion to a version later than 2021.19.

Fix

SSRF

Weakness Enumeration

Related Identifiers

CVE-2025-54234

Affected Products

Coldfusion