ColdFusionMX has been reported prone to a cross-site scripting vulnerability, under some circumstances. The issue has been reported to present itself in web sites that harness the default ColdFusionMX Site-Wide Error Handler page, the default ColdFusionMX Missing Template Handler has additionally been reported vulnerable. This vulnerability may be exploited by malicious attackers, to execute arbitrary HTML or Script code in the context of the affected site, in the browsers of unsuspecting users.
ColdFusionMX has been reported prone to a cross-site scripting vulnerability, under some circumstances. The issue has been reported to present itself in web sites that harness the default ColdFusionMX Site-Wide Error Handler page, the default ColdFusionMX Missing Template Handler has additionally been reported vulnerable. This vulnerability may be exploited by malicious attackers, to execute arbitrary HTML or Script code in the context of the affected site, in the browsers of unsuspecting users.