vulns.coMCP

← CVE intelligence

CVE-2024-20767 - Adobe ColdFusion Improper Access Control Vulnerability

Adobe ColdFusion contains an improper access control vulnerability that could allow an attacker to access or modify restricted files via an internet-exposed admin panel.

Severity
critical
Product
Adobe ColdFusion
Published
2024-12-16
EPSS
0.985
CISA KEV
Known exploited
Ransomware
Known campaign use

References and validation

Entries are refreshed from CISA KEV and FIRST EPSS. Validate applicability before testing.