cve/2023/CVE-2023-26361.md

18 lines
982 B
Markdown
Raw Normal View History

2024-06-10 07:22:43 +00:00
### [CVE-2023-26361](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-26361)
![](https://img.shields.io/static/v1?label=Product&message=ColdFusion&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=%3C%3D%20CF2018U15%2C%20CF2021U5%20&color=brighgreen)
![](https://img.shields.io/static/v1?label=Vulnerability&message=Improper%20Limitation%20of%20a%20Pathname%20to%20a%20Restricted%20Directory%20('Path%20Traversal')%20(CWE-22)&color=brighgreen)
### Description
Adobe ColdFusion versions 2018 Update 15 (and earlier) and 2021 Update 5 (and earlier) are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in Arbitrary file system read. Exploitation of this issue does not require user interaction, but does require administrator privileges.
### POC
#### Reference
No PoCs from references.
#### Github
- https://github.com/jakabakos/CVE-2023-26360-adobe-coldfusion-rce-exploit