← Back to browse · API

CVE-2023-38203

Severity
CRITICAL
CVSS
9.8
EPSS
0.96534
Risk score
58.79
CISA KEV
Yes
PoC
No
Published
2023-07-20
Modified
2025-10-21
First seen
2026-08-07
Aliases
EUVD-2023-42023, GHSA-4VP5-7P37-Q66W
Products
Adobe:ColdFusion, Adobe:ColdFusion 0 ≤cf2023U1
Sources
cisa.gov CVE-2023-38203
euvd EUVD-2023-42023

Description

Adobe ColdFusion versions 2018u17 (and earlier), 2021u7 (and earlier) and 2023u1 (and earlier) are affected by a Deserialization of Untrusted Data vulnerability that could result in Arbitrary code execution. Exploitation of this issue does not require user interaction.

References