ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read and write access. Exploitation of this issue does not require user interaction and scope is unchanged.
Metrics
Affected Vendors & Products
References
History
Tue, 09 Dec 2025 23:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read and write access. Exploitation of this issue does not require user interaction and scope is unchanged. | |
| Title | ColdFusion | Improper Input Validation (CWE-20) | |
| Weaknesses | CWE-20 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: adobe
Published: 2025-12-09T23:41:08.641Z
Updated: 2025-12-09T23:41:08.641Z
Reserved: 2025-10-01T17:52:06.976Z
Link: CVE-2025-61809
No data.
Status : Received
Published: 2025-12-10T00:16:09.273
Modified: 2025-12-10T00:16:09.273
Link: CVE-2025-61809
No data.