CVE-2023-44352
Unauthenticate Reflected XSS on Adobe Coldfusion 2018 - 2021 - 2023 last version
Record summary
CVE-2023-44352 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.
Description
Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an unauthenticated attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Dec 26, 2025 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Sep 16, 2024 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
ColdFusionBrowse Adobe / ColdFusionDefault status: affected | VulnCheck, CVE List | Through 2021.11 | affected |
Nuclei templates
1ProjectDiscoveryMEDIUMAdobe Coldfusion - Cross-Site ScriptingCVSS 6.1
Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an unauthenticated attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser
Impact
Unauthenticated attackers can inject malicious JavaScript through crafted URLs to execute code in victim browsers, potentially stealing ColdFusion administrator session cookies and gaining access to sensitive application configurations.
Remediation
Update Adobe ColdFusion to version 2023.6 or 2021.12 or later that properly escapes URLs in the CFIDE administrator and wizards interfaces.
Source: ProjectDiscovery