Description
ColdFusion allows an unauthenticated user to upload arbitrary files. An attacker can exploit it to achieve remote code execution.
Remediation
Upgrade to the latest version of ColdFusion
References
Related Vulnerabilities
DotCMS unrestricted file upload (CVE-2022-26352)
WordPress Plugin N-Media Post Front-end Form Arbitrary File Upload (1.0)
WordPress Plugin Delete All Comments Arbitrary File Upload (2.0)
WordPress Plugin PHP Event Calendar for WordPress Arbitrary File Upload (1.6)
WordPress Plugin Image News slider 'upload.php' Arbitrary File Upload (3.3)