CVE-2018-4941: XSS
Adobe ColdFusion Update 5 and earlier versions, ColdFusion 11 Update 13 and earlier versions have an exploitable Cross-Site Scripting vulnerability. Successful exploitation could lead to information disclosure.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-4941?
CVE-2018-4941 has a moderate severity rating, categorized as a cross-site scripting vulnerability.
How do I fix CVE-2018-4941?
To mitigate CVE-2018-4941, update to the latest version of Adobe ColdFusion, specifically versions after Update 5 for ColdFusion 11 and versions after Update 5 for ColdFusion 2016.
What types of systems are affected by CVE-2018-4941?
CVE-2018-4941 affects Adobe ColdFusion 11 and ColdFusion 2016 versions prior to their respective Update 6 releases.
What could an attacker do by exploiting CVE-2018-4941?
Exploitation of CVE-2018-4941 could allow an attacker to disclose sensitive information through cross-site scripting.
Is CVE-2018-4941 present in Adobe ColdFusion's later versions?
No, CVE-2018-4941 is not present in Adobe ColdFusion versions released after the necessary updates addressed the vulnerability.