CVE-2023-44352: Unauthenticate Reflected XSS on Adobe Coldfusion 2018 - 2021 - 2023 last version
Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an unauthenticated attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this Adobe ColdFusion vulnerability?
The vulnerability ID for this Adobe ColdFusion vulnerability is CVE-2023-44352.
What is the severity of CVE-2023-44352?
The severity of CVE-2023-44352 is medium.
Which versions of Adobe ColdFusion are affected by CVE-2023-44352?
Adobe ColdFusion versions 2023.5 and earlier, as well as 2021.11 and earlier, are affected by CVE-2023-44352.
What is the impact of CVE-2023-44352?
CVE-2023-44352 allows an unauthenticated attacker to execute malicious JavaScript on a vulnerable page.
Where can I find more information about CVE-2023-44352?
You can find more information about CVE-2023-44352 in the Adobe ColdFusion security bulletin APSB23-52.