CVE-2025-61808
BaseFortify
Publication date: 2025-12-10
Last updated on: 2025-12-12
Assigner: Adobe Systems Incorporated
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| adobe | coldfusion | 2021.22 |
| adobe | coldfusion | 2023.16 |
| adobe | coldfusion | 2025.4 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-434 | The product allows the upload or transfer of dangerous file types that are automatically processed within its environment. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is an Unrestricted Upload of File with Dangerous Type in ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier. It allows a high privileged attacker to upload files without restriction, potentially leading to arbitrary code execution. Exploiting this vulnerability does not require any user interaction and changes the security scope.
How can this vulnerability impact me? :
The vulnerability can lead to arbitrary code execution by a high privileged attacker, which means an attacker could run malicious code on the affected system. This can compromise confidentiality, integrity, and availability of the system and data, potentially leading to severe security breaches.