Description
ColdFusion is vulnerable to the XSS (cross-site scripting). It does not properly sanitize user input in the path.
Remediation
Upgrade to the latest version of ColdFusion
References
Related Vulnerabilities
Ruby on Rails Improper Input Validation Vulnerability (CVE-2011-2929)
Zope Web Application Server Other Vulnerability (CVE-2012-5486)
phpMyAdmin Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2016-5734)
WordPress Ultimate Member Plugin CVE-2020-36170 Vulnerability (CVE-2020-36170)