VYPR
Unrated severityNVD Advisory· Published Jun 12, 2019· Updated Aug 4, 2024

CVE-2019-7838

CVE-2019-7838

Description

ColdFusion versions Update 3 and earlier, Update 10 and earlier, and Update 18 and earlier have a file extension blacklist bypass vulnerability. Successful exploitation could lead to arbitrary code execution.

Affected products

2
  • Adobe Inc./Coldfusionllm-fuzzy2 versions
    <=2018 Update 3, <=2016 Update 10, <=11 Update 18+ 1 more
    • (no CPE)range: <=2018 Update 3, <=2016 Update 10, <=11 Update 18
    • (no CPE)range: Update 3 and earlier, Update 10 and earlier, and Update 18 and earlier versions

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.