HTTP: Adobe ColdFusion CKEditor Unrestricted File Upload

An unrestricted file upload vulnerability has been reported in the CKEditor component of Adobe ColdFusion. Successful exploitation results in the execution of the malicious file on the server.

Extended Description

Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have an unrestricted file upload vulnerability. Successful exploitation could lead to arbitrary code execution.

Affected Products

Adobe coldfusion

References

CVE: CVE-2018-15961

Short Name
HTTP:MISC:ADOBE-UPLOAD
Severity
Major
Recommended
True
Recommended Action
Drop
Category
HTTP
Keywords
Adobe CKEditor CVE-2018-15961 ColdFusion File Unrestricted Upload
Release Date
11/27/2018
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3337
False Positive
Unknown
Vendors

Adobe

CVSS Score

10.0

Found a potential security threat?