Description
Due to a vulnerability in ColdFusion components(.cfc) metadata handling, an unauthenticated attacker can execute arbitrary code or read files on the server
Remediation
Upgrade to the latest version of Adobe ColdFusion
References
Related Vulnerabilities
osTicket Improper Neutralization of Formula Elements in a CSV File Vulnerability (CVE-2019-14749)
WordPress 4.5.x Multiple Vulnerabilities (4.5 - 4.5.24)
WordPress Plugin Frontend File Manager Arbitrary File Upload (3.7)
WordPress URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2018-10101)