← Back to browse · API

CVE-2022-38418

Severity
CRITICAL
CVSS
9.8
EPSS
0.80023
Risk score
67.21
CISA KEV
No
PoC
No
Published
2022-10-14
Modified
2025-04-23
First seen
2026-08-07
Aliases
EUVD-2022-41003, GHSA-R25Q-PVVV-QRF3
Products
Adobe:ColdFusion unspecified ≤CF2018u14, Adobe:ColdFusion unspecified ≤CF2021U4, Adobe:ColdFusion unspecified ≤None
Sources
euvd EUVD-2022-41003

Description

Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction.

References