CyberSec.Space Logo
返回 CVE 浏览器

CVE-2025-61813

HIGH
8.2
CVSS Severity Score
EPSS Score0.0350%
EPSS Percentile21.91th
Published2025年12月10日
Last Modified2026年6月1日

Vulnerability Description

ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files on the server. Exploitation of this issue does requires user interaction and scope is changed.

Affected Platforms (CPE)

📦
Adobe

Coldfusion

= 2021
📦
Adobe

Coldfusion

= 2021
📦
Adobe

Coldfusion

= 2021
📦
Adobe

Coldfusion

= 2021
📦
Adobe

Coldfusion

= 2021
📦
Adobe

Coldfusion

= 2021
📦
Adobe

Coldfusion

= 2021
📦
Adobe

Coldfusion

= 2021
📦
Adobe

Coldfusion

= 2021
📦
Adobe

Coldfusion

= 2021
📦
Adobe

Coldfusion

= 2021
📦
Adobe

Coldfusion

= 2021
📦
Adobe

Coldfusion

= 2021
📦
Adobe

Coldfusion

= 2021
📦
Adobe

Coldfusion

= 2021
📦
Adobe

Coldfusion

= 2021
📦
Adobe

Coldfusion

= 2021
📦
Adobe

Coldfusion

= 2021
📦
Adobe

Coldfusion

= 2021
📦
Adobe

Coldfusion

= 2021
📦
Adobe

Coldfusion

= 2021
📦
Adobe

Coldfusion

= 2021
📦
Adobe

Coldfusion

= 2021
📦
Adobe

Coldfusion

= 2023
📦
Adobe

Coldfusion

= 2023
📦
Adobe

Coldfusion

= 2023
📦
Adobe

Coldfusion

= 2023
📦
Adobe

Coldfusion

= 2023
📦
Adobe

Coldfusion

= 2023
📦
Adobe

Coldfusion

= 2023
📦
Adobe

Coldfusion

= 2023
📦
Adobe

Coldfusion

= 2023
📦
Adobe

Coldfusion

= 2023
📦
Adobe

Coldfusion

= 2023
📦
Adobe

Coldfusion

= 2023
📦
Adobe

Coldfusion

= 2023
📦
Adobe

Coldfusion

= 2023
📦
Adobe

Coldfusion

= 2023
📦
Adobe

Coldfusion

= 2023
📦
Adobe

Coldfusion

= 2023
📦
Adobe

Coldfusion

= 2025
📦
Adobe

Coldfusion

= 2025
📦
Adobe

Coldfusion

= 2025
📦
Adobe

Coldfusion

= 2025
📦
Adobe

Coldfusion

= 2025

References & Advisories

相关漏洞威胁