CVE-2025-61813: ColdFusion | Improper Restriction of XML External Entity Reference ('XXE') (CWE-611)
ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files on the server. Exploitation of this issue does requires user interaction and scope is changed.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-61813?
CVE-2025-61813 has a high severity due to its potential to allow unauthorized access to sensitive files on the server.
How do I fix CVE-2025-61813?
To fix CVE-2025-61813, update Adobe ColdFusion to a version later than 2025.4, 2023.16, or 2021.22.
What types of systems are affected by CVE-2025-61813?
CVE-2025-61813 affects Adobe ColdFusion versions 2025.4 and earlier, including 2023.16 and 2021.22.
What are the potential impacts of CVE-2025-61813?
The potential impacts of CVE-2025-61813 include arbitrary file system read, leading to exposure of sensitive data.
What is an XML External Entity (XXE) vulnerability related to CVE-2025-61813?
The XML External Entity (XXE) vulnerability in CVE-2025-61813 allows an attacker to manipulate XML input to access server files.