Record summary

CVE-2023-44352 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.

Description

Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an unauthenticated attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Dec 26, 2025 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Sep 16, 2024 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

Default status: affected

VulnCheck, CVE ListThrough 2021.11affected

Nuclei templates

1
ProjectDiscoveryMEDIUMAdobe Coldfusion - Cross-Site ScriptingCVSS 6.1

Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an unauthenticated attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser

Impact

Unauthenticated attackers can inject malicious JavaScript through crafted URLs to execute code in victim browsers, potentially stealing ColdFusion administrator session cookies and gaining access to sensitive application configurations.

Remediation

Update Adobe ColdFusion to version 2023.6 or 2021.12 or later that properly escapes URLs in the CFIDE administrator and wizards interfaces.

WeaknessesCWE-79
Authorspwnwithlove
Template tagscvecve2023coldfusionadobexssvulnvkev
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:adobe:coldfusion:*:*:*:*:*:*:*:*
Shodan: http.component:"Adobe Coldfusion"
Shodan: http.component:"adobe coldfusion"
Shodan: http.title:"coldfusion administrator login"
Shodan: cpe:"cpe:2.3:a:adobe:coldfusion"
FOFA: title="coldfusion administrator login"
FOFA: app="adobe-coldfusion"
Google: intitle:"coldfusion administrator login"

Source: ProjectDiscovery

References

2