CVE-2020-3767
MEDIUMColdFusion 2016 and 2018 - Denial of Service via Insufficient Input Validation
Title source: llmDescription
ColdFusion versions ColdFusion 2016, and ColdFusion 2018 have an insufficient input validation vulnerability. Successful exploitation could lead to application-level denial-of-service (dos).
References (1)
Core 1
Core References
Vendor Advisory x_refsource_confirm
https://helpx.adobe.com/security/products/coldfusion/apsb20-18.html
Scores
CVSS v3
6.5
EPSS
0.0347
EPSS Percentile
87.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Details
CWE
CWE-20
Status
published
Products (2)
adobe/coldfusion
2016 (15 CPE variants)
adobe/coldfusion
2018 (9 CPE variants)
Published
Jun 26, 2020
Tracked Since
Feb 18, 2026