Description
ColdFusion is vulnerable to the XSS (cross-site scripting). It does not properly sanitize user input in the path.
Remediation
Upgrade to the latest version of ColdFusion
References
Related Vulnerabilities
MySQL CVE-2015-0505 Vulnerability (CVE-2015-0505)
Moodle Permissions, Privileges, and Access Controls Vulnerability (CVE-2015-5341)
SharePoint Origin Validation Error Vulnerability (CVE-2020-16952)
WordPress CVE-2017-1001000 Vulnerability (CVE-2017-1001000)
OpenSSL Permissions, Privileges, and Access Controls Vulnerability (CVE-2011-1473)