ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to a security feature bypass. An attacker could exploit this vulnerability to access files and directories that are stored outside the intended restricted directory. Exploitation of this issue requires user interaction.
CVE ID: CVE-2025-30290
CVSS Base Severity: HIGH
CVSS Base Score: 8.7
CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:H
Vendor: Adobe
Product: ColdFusion
EPSS Score: 0.09% (probability of being exploited)
EPSS Percentile: 27.52% (scored less or equal to compared to others)
EPSS Date: 2025-04-21 (when was this score calculated)
SSVC Exploitation: none
SSVC Technical Impact: partial
SSVC Automatable: false