7.5
CVSSv3

CVE-2022-42341

Published: 14/10/2022 Updated: 18/10/2022
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

Adobe ColdFusion versions Update 14 (and previous versions) and Update 4 (and previous versions) are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could result in arbitrary file system read. Exploitation of this issue does not require user interaction.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

adobe coldfusion 2018

adobe coldfusion 2021