#VU18738 Arbitrary file upload in ColdFusion - CVE-2019-7838
Published: June 11, 2019
ColdFusion
Adobe
Description
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to an error when processing file uplaods. A remote attacker can bypass file extensions blacklist, upload and execute arbitrary file on the server.
Note: exploitation of this vulnerability is possible if file upload directory is web accessible.