Vulnerability Database

289,697

Total vulnerabilities in the database

CVE-2023-44352

Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an unauthenticated attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.

  • Published: Nov 17, 2023
  • Updated: Nov 24, 2023
  • CVE: CVE-2023-44352
  • Severity: Medium
  • Exploit:

CVSS v3:

  • Severity: Medium
  • Score: 6.1
  • AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Software From Fixed in
adobe / coldfusion 2021 2021.x
adobe / coldfusion 2021-update1 2021-update1.x
adobe / coldfusion 2021-update2 2021-update2.x
adobe / coldfusion 2021-update3 2021-update3.x
adobe / coldfusion 2021-update4 2021-update4.x
adobe / coldfusion 2021-update5 2021-update5.x
adobe / coldfusion 2021-update6 2021-update6.x
adobe / coldfusion 2021-update7 2021-update7.x
adobe / coldfusion 2023-update1 2023-update1.x
adobe / coldfusion 2023 2023.x
adobe / coldfusion 2023-update2 2023-update2.x
adobe / coldfusion 2021-update8 2021-update8.x
adobe / coldfusion 2021-update9 2021-update9.x
adobe / coldfusion 2021-update10 2021-update10.x
adobe / coldfusion 2021-update11 2021-update11.x
adobe / coldfusion - 2021
adobe / coldfusion 2023-update3 2023-update3.x
adobe / coldfusion 2023-update4 2023-update4.x
adobe / coldfusion 2023-update5 2023-update5.x