S4E just found a high top 10 tcp port service scan
medium·Product Based Web Vulnerabilities·Updated Dec 16, 2023

CVE-2021-21087 Scanner

CVE-2021-21087 scanner - Cross-Site Scripting (XSS) vulnerability in Adobe ColdFusion

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
0
Times Used
by S4E users
0
Assets Scanned
domains & IPs
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-21087
5.4
CVSSmedium
Exploitable remotely over the internet · low-privilege account sufficient · user interaction needed.

Adobe Coldfusion versions 2016 (update 16 and earlier), 2018 (update 10 and earlier) and 2021.0.0.323925 are affected by an Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability. An attacker could abuse this vulnerability to execute arbitrary JavaScript code in context of the current user. Exploitation of this issue requires user interaction.

Attack Vector
Network
Privileges Req.
Low
User Interaction
Required
Affected
ColdFusionby Adobe
unspecified
Updated Aug 19, 2026View on NVD →
Detail

Adobe ColdFusion is a popular web development language used for creating dynamic web pages, web applications and services. It is widely used by developers for its ease of use, powerful features and the ability to integrate with other technologies. Adobe ColdFusion has been around for over two decades and has undergone several updates to stay relevant in the ever-changing digital landscape.

One of the latest updates, Adobe ColdFusion 2021.0.0.323925, has recently been found to contain a serious vulnerability known as CVE-2021-21087. This vulnerability is caused by improper neutralization of input during web page generation, also known as Cross-site Scripting (XSS). Exploiting this vulnerability allows attackers to inject malicious code into web pages, exploiting the trust that users have in the website.

The exploitation of this vulnerability can lead to a variety of disastrous consequences, ranging from the theft of sensitive information to complete control over the compromised system. Attackers can gather sensitive information such as credit card numbers, login credentials and personal information that they can use to launch further attacks. They can also hijack user accounts, inject malvertising, install malware and perform other malicious actions that can compromise the security of the user and the system.

At s4e.io, we provide a comprehensive digital asset security platform that empowers users to protect their digital assets from various threats, including vulnerabilities like the CVE-2021-21087. Our platform comes with pro features that allow users to conduct vulnerability scans, malware detection, and other security tests to ensure the utmost safety of their digital assets.

 

REFERENCES

Solution Advice

Fortunately, there are a number of precautions that can help mitigate the risk of exploitation of the CVE-2021-21087 vulnerability. These include:

  • Installing the latest updates and patches for Adobe ColdFusion.
  • Enabling input validation and encoding.
  • Disabling the HTTP TRACE method.
  • Implementing Content Security Policy (CSP) and HTTP Strict Transport Security (HSTS).
  • Using a web application firewall (WAF)  as a complementary protection layer.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.