Description
ColdFusion is vulnerable to the XSS (cross-site scripting). It does not properly sanitize user input in the path.
Remediation
Upgrade to the latest version of ColdFusion
References
Related Vulnerabilities
WordPress Plugin WP Helper Premium Cross-Site Scripting (4.2)
WordPress Plugin Tutor LMS-eLearning and online course solution Cross-Site Scripting (1.9.10)
PHP Improper Restriction of XML External Entity Reference Vulnerability (CVE-2013-1824)
Roundcube Cross-site Request Forgery (CSRF) Vulnerability (CVE-2016-4069)
Magento Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2019-7947)