CVE-2025-30294: ColdFusion | Improper Input Validation (CWE-20)
ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Input Validation vulnerability that could result in a security feature bypass. A high-privileged attacker could leverage this vulnerability to bypass security protections and gain unauthorized read access. Exploitation of this issue does not require user interaction and scope is changed.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-30294?
CVE-2025-30294 has been classified with a severity rating indicating a significant risk due to improper input validation that allows security feature bypass.
How do I fix CVE-2025-30294?
To fix CVE-2025-30294, upgrade to the latest version of Adobe ColdFusion that addresses the improper input validation vulnerability.
Which versions of Adobe ColdFusion are affected by CVE-2025-30294?
CVE-2025-30294 affects Adobe ColdFusion versions 2023.12, 2021.18, and 2025.0 and earlier.
What are the potential impacts of exploiting CVE-2025-30294?
Exploitation of CVE-2025-30294 could allow attackers to bypass security measures and gain unauthorized access to sensitive data.
Is CVE-2025-30294 being actively exploited in the wild?
As of now, there is no confirmed evidence that CVE-2025-30294 is being actively exploited in the wild, but it remains a critical vulnerability that should be addressed promptly.