← Back to browse · API

CVE-2024-20767

Severity
HIGH
CVSS
7.4
EPSS
0.98514
Risk score
59.48
CISA KEV
Yes
PoC
No
Published
2024-03-18
Modified
2025-10-21
First seen
2026-08-07
Aliases
EUVD-2024-18482, GHSA-R73P-8GX8-7PVG
Products
Adobe:ColdFusion, Adobe:ColdFusion 0 ≤2021.12
Sources
cisa.gov CVE-2024-20767
euvd EUVD-2024-18482

Description

ColdFusion versions 2023.6, 2021.12 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary file system read. An attacker could leverage this vulnerability to access or modify restricted files. Exploitation of this issue does not require user interaction. Exploitation of this issue requires the admin panel be exposed to the internet.

References