CVE-2019-7092: XSS
Published May 24, 2019
·Updated
ColdFusion versions Update 1 and earlier, Update 7 and earlier, and Update 15 and earlier have a cross site scripting vulnerability. Successful exploitation could lead to information disclosure .
Affected Software
26 affected components
Adobe ColdFusion=11.0
Adobe ColdFusion=11.0-update1
Adobe ColdFusion=11.0-update10
Adobe ColdFusion=11.0-update11
Adobe ColdFusion=11.0-update12
Adobe ColdFusion=11.0-update13
Adobe ColdFusion=11.0-update14
Adobe ColdFusion=11.0-update15
Adobe ColdFusion=11.0-update2
Adobe ColdFusion=11.0-update3
Adobe ColdFusion=11.0-update4
Adobe ColdFusion=11.0-update5
Adobe ColdFusion=11.0-update6
Adobe ColdFusion=11.0-update7
Adobe ColdFusion=11.0-update8
Adobe ColdFusion=11.0-update9
Adobe ColdFusion=2016
Adobe ColdFusion=2016-update1
Adobe ColdFusion=2016-update2
Adobe ColdFusion=2016-update3
Adobe ColdFusion=2016-update4
Adobe ColdFusion=2016-update5
Adobe ColdFusion=2016-update6
Adobe ColdFusion=2016-update7
Adobe ColdFusion=2018
Adobe ColdFusion=2018-update1
Event History
May 24, 2019
CVE Published
via MITRE·06:42 PM
Data Sourced
via MITRE·06:42 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2019-7092?
The severity of CVE-2019-7092 is medium with a CVSS score of 6.1.
2
How can CVE-2019-7092 be exploited?
CVE-2019-7092 can be exploited through cross site scripting (XSS) attacks.
3
What is the impact of CVE-2019-7092?
Successful exploitation of CVE-2019-7092 can lead to information disclosure.
4
Which versions of ColdFusion are affected by CVE-2019-7092?
ColdFusion versions Update 1 and earlier, Update 7 and earlier, and Update 15 and earlier are affected by CVE-2019-7092.
5
Where can I find more information about CVE-2019-7092?
More information about CVE-2019-7092 can be found at: [https://helpx.adobe.com/security/products/coldfusion/apsb19-10.html](https://helpx.adobe.com/security/products/coldfusion/apsb19-10.html)