CVE-2025-61808: ColdFusion | Unrestricted Upload of File with Dangerous Type (CWE-434)
ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could lead to arbitrary code execution by a high priviledged attacker. Exploitation of this issue does not require user interaction and scope is changed.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-61808?
CVE-2025-61808 is considered to have a high severity due to its potential for arbitrary code execution.
How do I fix CVE-2025-61808?
To fix CVE-2025-61808, update Adobe ColdFusion to versions 2025.5, 2023.17, or 2021.23 or later.
What products are affected by CVE-2025-61808?
CVE-2025-61808 affects Adobe ColdFusion versions 2025.4, 2023.16, and 2021.22 or earlier.
Can CVE-2025-61808 be exploited remotely?
Yes, CVE-2025-61808 can be exploited remotely without requiring user interaction.
What type of vulnerability is CVE-2025-61808?
CVE-2025-61808 is classified as an Unrestricted Upload of File with Dangerous Type vulnerability.