CVE-2024-20767

HIGH KEV NUCLEI

CVE-2024-20767 - Adobe Coldfusion Arbitrary File Read

Title source: metasploit

Description

ColdFusion versions 2023.6, 2021.12 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary file system read. An attacker could leverage this vulnerability to access or modify restricted files. Exploitation of this issue does not require user interaction. Exploitation of this issue requires the admin panel be exposed to the internet.

Exploits (7)

exploitdb WORKING POC
by İbrahimsql · pythonwebappsmultiple
https://www.exploit-db.com/exploits/52387
nomisec WORKING POC 34 stars
by yoryio · infoleak
https://github.com/yoryio/CVE-2024-20767
nomisec WORKING POC 9 stars
by Chocapikk · infoleak
https://github.com/Chocapikk/CVE-2024-20767
nomisec WORKING POC 1 stars
by Praison001 · infoleak
https://github.com/Praison001/CVE-2024-20767-Adobe-ColdFusion
nomisec WORKING POC 1 stars
by m-cetin · infoleak
https://github.com/m-cetin/CVE-2024-20767
nomisec WORKING POC
by alm6no5 · infoleak
https://github.com/alm6no5/CVE-2024-20767
metasploit WORKING POC
by ma4ter, yoryio, Christiaan Beek, jheysel-r7 · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/gather/coldfusion_pms_servlet_file_read.rb

Nuclei Templates (1)

Adobe ColdFusion - Arbitrary File Read
HIGHVERIFIEDby iamnoooob,rootxharsh,pdresearch
Shodan: http.component:"Adobe ColdFusion"

Scores

CVSS v3 7.4
EPSS 0.9404
EPSS Percentile 99.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

Details

CISA KEV 2024-12-16
VulnCheck KEV 2024-04-11
InTheWild.io 2024-12-16
ENISA EUVD EUVD-2024-18482
CWE
CWE-284
Status published
Products (2)
adobe/coldfusion 2021 (13 CPE variants)
adobe/coldfusion 2023 (7 CPE variants)
Published Mar 18, 2024
KEV Added Dec 16, 2024
Tracked Since Feb 18, 2026