CVE-2024-20767
CVSS 3.1 Score 7.4 of 10 (high)
Details
Published Mar 18, 2024
Updated: Dec 17, 2024
CWE ID 284
Summary
CVE-2024-20767 is a newly disclosed vulnerability affecting ColdFusion versions 2023.6, 2021.12, and older. This issue involves Improper Access Control, which enables attackers to perform arbitrary file system reads. By exploiting this vulnerability, malicious actors can access or modify restricted files, potentially leading to significant data compromise. Notably, this issue does not require user interaction and becomes exploitable only when the admin panel is exposed to the internet.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Adobe ColdFusion
Affected Vendors
- Adobe