← Back to browse · API

CVE-2023-44352

Severity
MEDIUM
CVSS
6.1
EPSS
0.84811
Risk score
54.08
CISA KEV
No
PoC
No
Published
2023-11-17
Modified
2024-10-29
First seen
2026-08-07
Aliases
EUVD-2023-48706, GHSA-FXVX-4HXP-C4WV
Products
Adobe:ColdFusion 0 ≤2021.11
Sources
euvd EUVD-2023-48706

Description

Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an unauthenticated attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.

References