Critical severity9.8NVD Advisory· Published Nov 24, 2020· Updated Jun 17, 2026
CVE-2020-15929
CVE-2020-15929
Description
In Ortus TestBox 2.4.0 through 4.1.0, unvalidated query string parameters passed to system/runners/HTMLRunner.cfm allow an attacker to write an arbitrary CFM file (within the application's context) containing attacker-defined CFML tags, leading to Remote Code Execution.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3Patches
Vulnerability mechanics
References
1- www.exploit-db.com/exploits/49077nvdExploitThird Party AdvisoryVDB Entry
News mentions
0No linked articles in our index yet.