ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Incorrect Authorization vulnerability that could lead to arbitrary code execution in the context of the current user. A high-privileged attacker could leverage this vulnerability to bypass security protections and execute code. Exploitation of this issue requires user interaction and scope is changed.
Metrics
Affected Vendors & Products
References
History
Wed, 14 May 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 13 May 2025 21:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Incorrect Authorization vulnerability that could lead to arbitrary code execution in the context of the current user. A high-privileged attacker could leverage this vulnerability to bypass security protections and execute code. Exploitation of this issue requires user interaction and scope is changed. | |
Title | ColdFusion | Incorrect Authorization (CWE-863) | |
Weaknesses | CWE-863 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: adobe
Published: 2025-05-13T20:49:31.403Z
Updated: 2025-05-15T04:01:41.254Z
Reserved: 2025-04-16T16:23:13.180Z
Link: CVE-2025-43565

Updated: 2025-05-14T14:10:26.803Z

Status : Received
Published: 2025-05-13T21:16:16.253
Modified: 2025-05-13T21:16:16.253
Link: CVE-2025-43565

No data.