First published: Tue May 13 2025(Updated: )
ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. A high-privileged attacker could leverage this vulnerability to bypass security mechanisms and execute code. Exploitation of this issue does not require user interaction and scope is changed.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe ColdFusion | <2025.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-43560 is classified as a high-severity vulnerability due to its potential to allow arbitrary code execution.
To fix CVE-2025-43560, update Adobe ColdFusion to the latest version beyond 2025.1 and apply any relevant security patches.
CVE-2025-43560 affects ColdFusion versions 2025.1, 2023.13, 2021.19, and earlier.
CVE-2025-43560 allows attackers to execute arbitrary code, which can compromise the integrity and confidentiality of the affected systems.
CVE-2025-43560 can be exploited by high-privileged attackers who can bypass security mechanisms due to improper input validation.