ShadowTrackr

Search the CVE vulnerability database

Look up vulnerabilities by software, product or CVE number.

1 result for “CVE-2020-10145”

CVEPublishedCVSSShadowTrackr CVSSSummary
CVE:
CVE-2020-10145
Published
2021-05-27
CVSS:
7.8
ShadowTrackr CVSS:
4.4
Summary:
The Adobe ColdFusion installer fails to set a secure access-control list (ACL) on the default installation directory, such as C:\ColdFusion2021\. By default, unprivileged users can create files in this directory structure, which creates a privilege-escalation vulnerability.