Adobe ColdFusion Pre-Auth RCE(s) — ProjectDiscovery Blog

blog.projectdiscovery.io · bugbountydaily · 1 year ago · research
quality 7/10 · good
0 net
For the latest updates on CVE-2023-29300 / CVE-2023-38203 / CVE-2023-38204, see the updates section Introduction The Adobe ColdFusion, widely recognized for its robust web development capabilities, recently released a critical security update. The update specifically targeted three security issues, among them, CVE-2023-29300, a highly concerning pre-authentication Remote Code Execution (RCE) vulnerability. This vulnerability poses a significant threat, allowing malicious actors to execute arb