Description
ColdFusion Administrator Login Page is publicly available to any IP address. A good security practice is to limit access to this page to localhost or a list of fixed IP addresses.
Remediation
Limit access to the ColdFusion Administrator Login Page to localhost or a list of fixed IP addresses.
References
Related Vulnerabilities
WordPress 4.7.x Multiple Vulnerabilities (4.7 - 4.7.19)
WordPress Plugin Backup Migration Information Disclosure (1.2.8)
RethinkDB administrative interface publicly exposed
WordPress 6.3.x Multiple Vulnerabilities (6.3 - 6.3.1)
Moodle Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2015-0211)