← Back to CVE List

CVE-2024-20767

Published: 2024-03-18T12:15Z
Last Modified: 2024-12-17T02:00Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
ColdFusion versions 2023.6, 2021.12 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary file system read. An attacker could leverage this vulnerability to access or modify restricted files. Exploitation of this issue does not require user interaction. Exploitation of this issue requires the admin panel be exposed to the internet. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt