CVE-2024-20767
ColdFusion | Improper Access Control (CWE-284)
Basic Information
- CVE State
- PUBLISHED
- Reserved Date
- December 04, 2023
- Published Date
- March 18, 2024
- Last Updated
- December 17, 2024
- Vendor
- Adobe
- Product
- ColdFusion
- Description
- ColdFusion versions 2023.6, 2021.12 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary file system read. An attacker could leverage this vulnerability to access or modify restricted files. Exploitation of this issue does not require user interaction. Exploitation of this issue requires the admin panel be exposed to the internet.
CVSS Scores
CVSS v3.1
7.4 - HIGH
Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
SSVC Information
- Exploitation
- active
- Automatable
- Yes
- Technical Impact
- partial
Known Exploited Vulnerability Information
Source | Added Date |
---|---|
CISA | 2024-12-16 00:00:00 UTC |
Scanner Integrations
Scanner | URL | Date Detected |
---|---|---|
Nuclei | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2024/CVE-2024-20767.yaml | 2025-04-26 00:00:00 UTC |
Potential Proof of Concepts
Warning: These PoCs have not been tested and could contain malware. Use at your own risk.
Chocapikk/CVE-2024-20767
Type: github • Created: 2024-03-26 19:17:14 UTC • Stars: 8
Exploit Toolkit for Adobe ColdFusion CVE-2024-20767 Vulnerability
yoryio/CVE-2024-20767
Type: github • Created: 2024-03-26 06:51:08 UTC • Stars: 34
Exploit for CVE-2024-20767 - Adobe ColdFusion