CVE-2024-53961

HIGH

ColdFusion <2021.17 - Path Traversal

Title source: llm
STIX 2.1

Description

ColdFusion versions 2023.11, 2021.17 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access files or directories that are outside of the restricted directory set by the application. This could lead to the disclosure of sensitive information or the manipulation of system data. Exploitation of this issue requires the admin panel be exposed to the internet.

References (1)

Core 1
Core References

Scores

CVSS v3 8.1
EPSS 0.0692
EPSS Percentile 91.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-22
Status published
Products (2)
adobe/coldfusion 2021 (18 CPE variants)
adobe/coldfusion 2023 (12 CPE variants)
Published Dec 23, 2024
Tracked Since Feb 18, 2026