CVE-2025-30293: ColdFusion | Improper Input Validation (CWE-20)
ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Input Validation vulnerability that could result in a security feature bypass. A high-privileged attacker could leverage this vulnerability to bypass security protections and gain unauthorized write access. Exploitation of this issue does not require user interaction and scope is changed.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-30293?
CVE-2025-30293 is considered a high severity vulnerability due to the risk of unauthorized access through security feature bypass.
How do I fix CVE-2025-30293?
To fix CVE-2025-30293, you should update your Adobe ColdFusion to the latest version beyond 2023.12.
What versions of Adobe ColdFusion are affected by CVE-2025-30293?
CVE-2025-30293 affects Adobe ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier.
What can an attacker do by exploiting CVE-2025-30293?
An attacker exploiting CVE-2025-30293 can bypass security measures and gain unauthorized access to affected systems.
Is there a workaround for CVE-2025-30293?
Currently, the recommended mitigation for CVE-2025-30293 is to apply the latest security patches and updates.