CVE-2018-15961: Adobe ColdFusion Unrestricted File Upload Vulnerability
Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have an unrestricted file upload vulnerability. Successful exploitation could lead to arbitrary code execution.
Other sources
Adobe ColdFusion contains an unrestricted file upload vulnerability that could allow for code execution.
— CISA
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this Adobe ColdFusion vulnerability?
The vulnerability ID is CVE-2018-15961.
What is the severity of CVE-2018-15961?
The severity of CVE-2018-15961 is critical with a severity value of 9.8.
Which versions of Adobe ColdFusion are affected by CVE-2018-15961?
Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier are affected by CVE-2018-15961.
What is the impact of CVE-2018-15961?
Successful exploitation of CVE-2018-15961 could lead to arbitrary code execution.
How can I fix CVE-2018-15961?
Update to Adobe ColdFusion July 2018 release (2018.0.1.310867), or apply Update 7 or later, or Update 15 or later.