Total vulnerabilities in the database
The Adobe ColdFusion installer fails to set a secure access-control list (ACL) on the default installation directory, such as C:\ColdFusion2021. By default, unprivileged users can create files in this directory structure, which creates a privilege-escalation vulnerability.
Software | From | Fixed in |
---|---|---|
adobe / coldfusion | 2018 | 2018.x |
adobe / coldfusion | 2016 | 2016.x |
adobe / coldfusion | 2021 | 2021.x |