Lucee 5.4.2.17 contains a reflected cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts through administrative interface parameters. Attackers can craft specific payloads targeting admin pages like server.cfm and web.cfm to execute arbitrary JavaScript in victim's browser sessions.
Metrics
Affected Vendors & Products
References
History
Mon, 15 Dec 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 15 Dec 2025 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Lucee 5.4.2.17 contains a reflected cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts through administrative interface parameters. Attackers can craft specific payloads targeting admin pages like server.cfm and web.cfm to execute arbitrary JavaScript in victim's browser sessions. | |
| Title | Lucee 5.4.2.17 Authenticated Reflected Cross-Site Scripting via Admin Interfaces | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2025-12-15T20:28:18.996Z
Updated: 2025-12-15T21:47:26.669Z
Reserved: 2025-12-13T14:25:04.999Z
Link: CVE-2023-53880
Updated: 2025-12-15T21:40:03.408Z
Status : Received
Published: 2025-12-15T21:15:50.853
Modified: 2025-12-15T21:15:50.853
Link: CVE-2023-53880
No data.