Loading HuntDB...

CVE-2023-26347 in https://████.mil/hax/..CFIDE/adminapi/administrator.cfc?method=getBuildNumber&_cfclient=true

High
U
U.S. Dept Of Defense
Submitted None
Reported by traveler5260

Vulnerability Details

Technical details and impact analysis

Improper Access Control - Generic
**Description:** Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An unauthenticated attacker could leverage this vulnerability to access the administration CFM and CFC endpoints. ## References https://nvd.nist.gov/vuln/detail/CVE-2023-26347 https://vuldb.com/?id.245747 ## Impact An attacker, without authentication, could exploit this vulnerability to gain access to the administration CFM and CFC endpoints. ## System Host(s) ██████████.mil ## Affected Product(s) and Version(s) https://█████.mil/hax/..CFIDE/adminapi/administrator.cfc?method=getBuildNumber&_cfclient=true ## CVE Numbers CVE-2023-26347 ## Steps to Reproduce Access to the https://████████.mil/hax/..CFIDE/adminapi/administrator.cfc?method=getBuildNumber&_cfclient=true site. ## Suggested Mitigation/Remediation Actions Check the [Release Note](https://helpx.adobe.com/security/products/coldfusion/apsb23-52.html) and upgrade the version of Adobe ColdFusion product

Related CVEs

Associated Common Vulnerabilities and Exposures

Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An unauthenticated attacker could leverage this vulnerability to access the administration CFM and CFC endpoints. Exploitation of this issue does not require user interaction.

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Improper Access Control - Generic