CVE-2023-26347 in https://████.mil/hax/..CFIDE/adminapi/administrator.cfc?method=getBuildNumber&_cfclient=true

Disclosed: 2024-07-19 14:16:46 By traveler5260 To deptofdefense
High
Vulnerability Details
**Description:** Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An unauthenticated attacker could leverage this vulnerability to access the administration CFM and CFC endpoints. ## References https://nvd.nist.gov/vuln/detail/CVE-2023-26347 https://vuldb.com/?id.245747 ## Impact An attacker, without authentication, could exploit this vulnerability to gain access to the administration CFM and CFC endpoints. ## System Host(s) ██████████.mil ## Affected Product(s) and Version(s) https://█████.mil/hax/..CFIDE/adminapi/administrator.cfc?method=getBuildNumber&_cfclient=true ## CVE Numbers CVE-2023-26347 ## Steps to Reproduce Access to the https://████████.mil/hax/..CFIDE/adminapi/administrator.cfc?method=getBuildNumber&_cfclient=true site. ## Suggested Mitigation/Remediation Actions Check the [Release Note](https://helpx.adobe.com/security/products/coldfusion/apsb23-52.html) and upgrade the version of Adobe ColdFusion product
Actions
View on HackerOne
Report Stats
  • Report ID: 2518407
  • State: Closed
  • Substate: resolved
  • Upvotes: 11
Share this report