QID 150832
Date Published: 2024-03-14
QID 150832: Adobe ColdFusion Arbitrary File Read Vulnerability (CVE-2024-20767)
Adobe ColdFusion is an application server and a platform for building and deploying web and mobile applications.
Multiple versions of Adobe ColdFusion are affected by an Arbitrary File System Read vulnerability, Adobe has issued security updates addressing this vulnerability for ColdFusion versions 2023 and 2021.
Affected Products:
ColdFusion (2023 release) Update 6 and earlier versions.
ColdFusion (2021 release) Update 12 and earlier versions.
QID Detection Logic (Unauthenticated):
This QID sends HTTP GET request to "CFIDE/adminapi/administrator.cfc" endpoint and checks for vulnerable version of Adobe Coldfusion running on the target system.
Successful exploitation of this vulnerability could allow an attacker to read the contents of arbitrary files from the target system.
CVEs related to QID 150832
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| APSB24-14 |
|