S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2023-29300 Scanner

Detects 'Deserialization of Untrusted Data' vulnerability in Adobe ColdFusion affects v. 2018u16 (and earlier), 2021u6 (and earlier) and 2023.0.0.330468 (and earlier).

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
3.1k
Times Used
continuous scan runs
5.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2023-29300
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

Adobe ColdFusion versions 2018u16 (and earlier), 2021u6 (and earlier) and 2023.0.0.330468 (and earlier) are affected by a Deserialization of Untrusted Data vulnerability that could result in Arbitrary code execution. Exploitation of this issue does not require user interaction.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
ColdFusionby Adobe
0
Updated Aug 22, 2026View on NVD →
Detail

Adobe ColdFusion is a web development platform used to create dynamic and engaging websites, applications, and services. It is a popular software because it allows developers to build and deploy web applications quickly, easily, and securely. Adobe ColdFusion has been a trusted product for web developers for years, but like any software, it is not immune to flaws. Recently, a critical vulnerability known as CVE-2023-29300 was discovered in the platform that has put users at risk.

CVE-2023-29300 is a Deserialization of Untrusted Data vulnerability that affects Adobe ColdFusion. This vulnerability can be exploited remotely by an attacker who sends malicious data to the application. If this vulnerability is exploited, an attacker could gain access to sensitive information, execute arbitrary code, or take over the entire system. 

The potential dangers of this vulnerability are severe and could have wide-reaching consequences. Attackers could gain access to confidential data, such as login credentials, financial information, and personal information. The vulnerability could also be used to deploy other malware or ransomware, causing significant disruption to businesses, organizations, and individuals alike. The exploitation of CVE-2023-29300 could have a highly damaging effect on the reputation of the company or individual who fell victim to it.

At s4e.io, our goal is to help businesses and individuals protect their digital assets from potential threats. Our platform features pro tools that enable us to provide clients with in-depth analysis of the security of their web applications and digital assets. We offer expert recommendations and guidance on how to address vulnerabilities, including CVE-2023-29300, quickly and efficiently. By relying on our services, businesses and individuals can proactively develop their cybersecurity systems and stay ahead of potential threats, knowing that they are always secure.

 

REFERENCES

Solution Advice

There are several precautions that can be taken to protect against this vulnerability, including:

  • Applying the latest security patches for Adobe ColdFusion
  • Restricting access to the administrative interface of the platform
  • Implementing secure coding practices in web applications developed on the platform
  • Performing regular vulnerability scans and security audits of digital assets
  • Educating staff and users on safe browsing practices and how to respond to suspicious activity.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2023-29300 scanner - Deserialization of Untrusted Data vulnerability in Adobe ColdFusion | S4E