CVE-2023-26347
CVE-2023-38205 issues | ColdFusion Admin Panel Access
Record summary
CVE-2023-26347 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.
Description
Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An unauthenticated attacker could leverage this vulnerability to access the administration CFM and CFC endpoints. Exploitation of this issue does not require user interaction.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · May 6, 2024 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Oct 15, 2024 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
ColdFusionBrowse Adobe / ColdFusionDefault status: affected | VulnCheck, CVE List | Through 2021.11 | affected |
Nuclei templates
1ProjectDiscoveryHIGHAdobe Coldfusion - Authentication BypassCVSS 7.5
Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An unauthenticated attacker could leverage this vulnerability to access the administration CFM and CFC endpoints. Exploitation of this issue does not require user interaction.
Impact
Unauthenticated attackers can bypass access controls to access Adobe ColdFusion administration endpoints, potentially allowing full control over the ColdFusion server and access to sensitive application data.
Remediation
Upgrade to Adobe ColdFusion 2023.6 or 2021.12 or later versions that address this access control vulnerability.
Source: ProjectDiscovery