← Back to browse · API

CVE-2024-41874

Severity
CRITICAL
CVSS
9.8
EPSS
0.30315
Risk score
49.81
CISA KEV
No
PoC
No
Published
2024-09-13
Modified
2024-09-16
First seen
2026-08-07
Aliases
EUVD-2024-39251, GHSA-PQQ8-7W9H-7G85
Products
Adobe:ColdFusion 0 ≤2021.15
Sources
euvd EUVD-2024-39251

Description

ColdFusion versions 2023.9, 2021.15 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability by providing crafted input to the application, which when deserialized, leads to execution of malicious code. Exploitation of this issue does not require user interaction.

References