← Back to browse · API

CVE-2025-30290

Severity
HIGH
CVSS
8.7
EPSS
0.17908
Risk score
41.07
CISA KEV
No
PoC
No
Published
2025-04-08
Modified
2025-05-09
First seen
2026-08-07
Aliases
EUVD-2025-14806, GHSA-3GXJ-2579-VRCC
Products
Adobe:ColdFusion 0 ≤2025.0
Sources
euvd EUVD-2025-14806

Description

ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to a security feature bypass. A high privileged attacker could exploit this vulnerability to bypass security protections and gain unauthorized write and delete access. Exploitation of this issue does not require user interaction and scope is changed.

References