CVE-2023-26347 in https://████.mil/hax/..CFIDE/adminapi/administrator.cfc?method=getBuildNumber&_cfclient=true
High
Vulnerability Details
**Description:**
Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An unauthenticated attacker could leverage this vulnerability to access the administration CFM and CFC endpoints.
## References
https://nvd.nist.gov/vuln/detail/CVE-2023-26347
https://vuldb.com/?id.245747
## Impact
An attacker, without authentication, could exploit this vulnerability to gain access to the administration CFM and CFC endpoints.
## System Host(s)
██████████.mil
## Affected Product(s) and Version(s)
https://█████.mil/hax/..CFIDE/adminapi/administrator.cfc?method=getBuildNumber&_cfclient=true
## CVE Numbers
CVE-2023-26347
## Steps to Reproduce
Access to the https://████████.mil/hax/..CFIDE/adminapi/administrator.cfc?method=getBuildNumber&_cfclient=true site.
## Suggested Mitigation/Remediation Actions
Check the [Release Note](https://helpx.adobe.com/security/products/coldfusion/apsb23-52.html) and upgrade the version of Adobe ColdFusion product
Actions
View on HackerOneReport Stats
- Report ID: 2518407
- State: Closed
- Substate: resolved
- Upvotes: 11