Description
ColdFusion Administrator Login Page is publicly available to any IP address. A good security practice is to limit access to this page to localhost or a list of fixed IP addresses.
Remediation
Limit access to the ColdFusion Administrator Login Page to localhost or a list of fixed IP addresses.
References
Related Vulnerabilities
PHP Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2015-8393)
Oracle Business Intelligence AuthBypass CVE-2019-2768
Moodle Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2017-2643)
WordPress Plugin Advanced Contact form 7 DB Information Disclosure (1.6.2)