← Voltar para CVEs
CVE-2025-49538
HIGH7.4
Descricao
ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by an XML Injection vulnerability that could lead to arbitrary file system read. An attacker can exploit this issue by injecting crafted XML or XPath queries to access unauthorized files or lead to denial of service. Exploitation of this issue does not require user interaction, and attack must have access to shared secrets.
Detalhes CVE
Pontuacao CVSS v3.17.4
SeveridadeHIGH
Vetor CVSSCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H
Vetor de ataqueNETWORK
ComplexidadeHIGH
Privilegios necessariosNONE
Interacao do usuarioNONE
Publicado7/8/2025
Ultima modificacao7/11/2025
Fontenvd
Avistamentos honeypot0
Produtos afetados
adobe:coldfusion
Fraquezas (CWE)
CWE-91
Referencias
https://helpx.adobe.com/security/products/coldfusion/apsb25-69.html(psirt@adobe.com)
Correlacoes IOC
Sem correlacoes registradas
This product uses data from the NVD API but is not endorsed or certified by the NVD.