← voltar
CVE-2021-21087

ColdFusion Improper neutralization of web input during page generation could lead to arbitrary JavaScript execution in the browser

CVSS 5.4 MEDIUMEPSS 37.1%CWE-79
Adobe Coldfusion versions 2016 (update 16 and earlier), 2018 (update 10 and earlier) and 2021.0.0.323925 are affected by an Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability. An attacker could abuse this vulnerability to execute arbitrary JavaScript code in context of the current user. Exploitation of this issue requires user interaction.
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Produtos afetados
Adobe · ColdFusion

Quer saber se a sua infraestrutura está exposta a isto?

Falar com a TrueHacking →