CVE-2023-26361: Adobe ColdFusion Directory Traversal Arbitrary file system read Vulnerability
Adobe ColdFusion versions 2018 Update 15 (and earlier) and 2021 Update 5 (and earlier) are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in Arbitrary file system read. Exploitation of this issue does not require user interaction, but does require administrator privileges.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2023-26361?
CVE-2023-26361 is a vulnerability in Adobe ColdFusion versions 2018 Update 15 (and earlier) and 2021 Update 5 (and earlier) that allows for Arbitrary file system read through a Path Traversal attack.
What is the severity of CVE-2023-26361?
The severity of CVE-2023-26361 is medium with a CVSS score of 4.9.
How does CVE-2023-26361 affect Adobe ColdFusion?
CVE-2023-26361 affects Adobe ColdFusion versions 2018 Update 15 (and earlier) and 2021 Update 5 (and earlier) by allowing an attacker to read arbitrary files on the system.
How can I fix CVE-2023-26361?
To fix CVE-2023-26361, it is recommended to update Adobe ColdFusion to the latest available version.
Where can I find more information about CVE-2023-26361?
More information about CVE-2023-26361 can be found on the Adobe Security Bulletin APSB23-25.