CVE-2018-15961criticalunder attackCWE-434

CVE-2018-15961: critical vulnerability in Adobe ColdFusion

Published · Updated

100Vexday Risk Score

Patch now. It under exploitation confirmed by CISA and has a working public exploit.

ssvc Actcvss 9.8epss 100%
from disclosure to weapon72 days
Published on NVDSep 25
1st PoC+72d
metasploitSep 11
CISA KEV+1135d
exploitation probability
100%top 1% of all CVEs
observed exploitation
yesCISA + VulnCheck
12 public exploit(s)
Action required by CISAfederal deadline: 2022-05-03

Apply updates per vendor instructions.

In short

Adobe ColdFusion allows attackers to upload files without proper restrictions, potentially leading to malicious code execution on the server. This is a critical flaw because it can give attackers complete control over the affected system.

Technical detail

An unrestricted file upload vulnerability (CWE-434) in Adobe ColdFusion enables attackers to bypass upload validation controls and execute arbitrary code on the server. Exploitation requires network access to the upload functionality; successful code execution compromises the entire application and underlying system integrity.

Summary generated and translated by AI from the official description.

The full analysis of this CVE is available in Portuguese →

Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have an unrestricted file upload vulnerability. Successful exploitation could lead to arbitrary code execution.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
Adobe · ColdFusion
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.