CVE-2019-7816

CRITICAL EXPLOITED IN THE WILD

ColdFusion <Update 2 - RCE

Title source: llm
STIX 2.1

Description

ColdFusion versions Update 2 and earlier, Update 9 and earlier, and Update 17 and earlier have a file upload restriction bypass vulnerability. Successful exploitation could lead to arbitrary code execution.

References (1)

Core 1
Core References

Scores

CVSS v3 9.8
EPSS 0.0482
EPSS Percentile 89.6%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

VulnCheck KEV 2019-03-01
InTheWild.io 2019-03-01
CWE
CWE-434
Status published
Products (3)
adobe/coldfusion 11.0 (18 CPE variants)
adobe/coldfusion 2016 (10 CPE variants)
adobe/coldfusion 2018 (3 CPE variants)
Published May 24, 2019
Tracked Since Feb 18, 2026