8.2

CVE-2025-30289

ColdFusion | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78)

ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could lead in arbitrary code execution by an attacker. A low privileged attacker with local access could leverage this vulnerability to bypass security protections and execute code. Exploitation of this issue requires user interaction in that a victim must be coerced into performing actions within the application. Scope is changed.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Adobe ≫ Coldfusion Version 2021 Update -
Adobe ≫ Coldfusion Version 2021 Update update1
Adobe ≫ Coldfusion Version 2021 Update update10
Adobe ≫ Coldfusion Version 2021 Update update11
Adobe ≫ Coldfusion Version 2021 Update update12
Adobe ≫ Coldfusion Version 2021 Update update13
Adobe ≫ Coldfusion Version 2021 Update update14
Adobe ≫ Coldfusion Version 2021 Update update15
Adobe ≫ Coldfusion Version 2021 Update update16
Adobe ≫ Coldfusion Version 2021 Update update17
Adobe ≫ Coldfusion Version 2021 Update update18
Adobe ≫ Coldfusion Version 2021 Update update2
Adobe ≫ Coldfusion Version 2021 Update update3
Adobe ≫ Coldfusion Version 2021 Update update4
Adobe ≫ Coldfusion Version 2021 Update update5
Adobe ≫ Coldfusion Version 2021 Update update6
Adobe ≫ Coldfusion Version 2021 Update update7
Adobe ≫ Coldfusion Version 2021 Update update8
Adobe ≫ Coldfusion Version 2021 Update update9
Adobe ≫ Coldfusion Version 2023 Update -
Adobe ≫ Coldfusion Version 2023 Update update1
Adobe ≫ Coldfusion Version 2023 Update update10
Adobe ≫ Coldfusion Version 2023 Update update11
Adobe ≫ Coldfusion Version 2023 Update update12
Adobe ≫ Coldfusion Version 2023 Update update2
Adobe ≫ Coldfusion Version 2023 Update update3
Adobe ≫ Coldfusion Version 2023 Update update4
Adobe ≫ Coldfusion Version 2023 Update update5
Adobe ≫ Coldfusion Version 2023 Update update6
Adobe ≫ Coldfusion Version 2023 Update update7
Adobe ≫ Coldfusion Version 2023 Update update8
Adobe ≫ Coldfusion Version 2023 Update update9
Adobe ≫ Coldfusion Version 2025 Update -
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 5.27% 0.918
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 8.2 1.5 6
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
Adobe 8.2 1.5 6
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

https://helpx.adobe.com/security/products/coldfusion/apsb25-15.html
Vendor Advisory