Description
Lucee Server is a dynamic, Java based (JSR-223), tag and scripting language used for rapid web application development.
Lucee Server versions older than 5.3.8.89 allow attackers to access authenticated CFM (ColdFusion) files directly. This allowed atackers to perform a lot of authenticated actions while being completely unauthenticated.
The file imgProcess.cfm is vulnerable to a path traversal vulnerability that allows an attacker to create a file anywhere on the server with attacker-controlled content. This can be easily escalated in RCE (Remote Code Execution) by creating malicious .cfm files.
Remediation
Upgrade to the latest version of Lucee Server to fix this issue.
References
Related Vulnerabilities
Fortigate SSL VPN Arbitrary File reading (CVE-2018-13379)
Multiple vulnerabilities reported in Parallels Plesk Sitebuilder
WordPress Plugin NextGEN Gallery-WordPress Gallery Local File Inclusion (2.1.7)
WordPress Plugin Blogtopdf Local File Inclusion (1.0.2)
WordPress Plugin WP e-Commerce Shop Styling Local File Inclusion (2.9.1)