Description
Due to a vulnerability in ColdFusion components(.cfc) metadata handling, an unauthenticated attacker can execute arbitrary code or read files on the server
Remediation
Upgrade to the latest version of Adobe ColdFusion
References
Related Vulnerabilities
Drupal Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2012-0825)
Omeka Server-Side Request Forgery (SSRF) Vulnerability (CVE-2023-3981)
WordPress 5.2.x Multiple Vulnerabilities (5.2 - 5.2.5)
WordPress Permissions, Privileges, and Access Controls Vulnerability (CVE-2009-2854)