First published: Mon Mar 22 2021(Updated: )
Adobe Coldfusion versions 2016 (update 16 and earlier), 2018 (update 10 and earlier) and 2021.0.0.323925 are affected by an Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability. An attacker could abuse this vulnerability to execute arbitrary JavaScript code in context of the current user. Exploitation of this issue requires user interaction.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe ColdFusion | =2016 | |
Adobe ColdFusion | =2016-update1 | |
Adobe ColdFusion | =2016-update10 | |
Adobe ColdFusion | =2016-update11 | |
Adobe ColdFusion | =2016-update12 | |
Adobe ColdFusion | =2016-update13 | |
Adobe ColdFusion | =2016-update14 | |
Adobe ColdFusion | =2016-update15 | |
Adobe ColdFusion | =2016-update16 | |
Adobe ColdFusion | =2016-update2 | |
Adobe ColdFusion | =2016-update3 | |
Adobe ColdFusion | =2016-update4 | |
Adobe ColdFusion | =2016-update5 | |
Adobe ColdFusion | =2016-update6 | |
Adobe ColdFusion | =2016-update7 | |
Adobe ColdFusion | =2016-update8 | |
Adobe ColdFusion | =2016-update9 | |
Adobe ColdFusion | =2018 | |
Adobe ColdFusion | =2018-update1 | |
Adobe ColdFusion | =2018-update10 | |
Adobe ColdFusion | =2018-update2 | |
Adobe ColdFusion | =2018-update3 | |
Adobe ColdFusion | =2018-update4 | |
Adobe ColdFusion | =2018-update5 | |
Adobe ColdFusion | =2018-update6 | |
Adobe ColdFusion | =2018-update7 | |
Adobe ColdFusion | =2018-update8 | |
Adobe ColdFusion | =2018-update9 | |
Adobe ColdFusion | =2021.0.0.323925 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this Adobe Coldfusion vulnerability is CVE-2021-21087.
The severity of CVE-2021-21087 is medium.
CVE-2021-21087 affects Adobe Coldfusion versions 2016 (update 16 and earlier), 2018 (update 10 and earlier), and 2021.0.0.323925.
CVE-2021-21087 allows an attacker to execute arbitrary JavaScript code.
Yes, Adobe has released a security update to address CVE-2021-21087. It is recommended to apply the latest update.