← Back

CVE-2021-21087

Published: Apr 15, 2021Modified: Jun 17, 2026

JSON object

Loading...
5.4
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.3 / Impact: 2.7
Source: NVD

Description

Adobe Coldfusion versions 2016 (update 16 and earlier), 2018 (update 10 and earlier) and 2021.0.0.323925 are affected by an Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability. An attacker could abuse this vulnerability to execute arbitrary JavaScript code in context of the current user. Exploitation of this issue requires user interaction.

Affected (29)

Products: Adobe: Coldfusion
1 product
Coldfusion
Configuration A
29 vulnerable
Vulnerable SoftwareAffected Versions
Adobe
Version 2016
Version 2016 update10
Version 2016 update11
Version 2016 update12
Version 2016 update13
Version 2016 update14
Version 2016 update15
Version 2016 update16
Version 2016 update1
Version 2016 update2
Version 2016 update3
Version 2016 update4
Version 2016 update5
Version 2016 update6
Version 2016 update7
Version 2016 update8
Version 2016 update9
Version 2018
Version 2018 update10
Version 2018 update1
Version 2018 update2
Version 2018 update3
Version 2018 update4
Version 2018 update5
Version 2018 update6
Version 2018 update7
Version 2018 update8
Version 2018 update9
Version 2021.0.0.323925

References (2)

Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory

Timeline

No history available yet.