Lucee 5.4.2.17 contains a reflected cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts through administrative interface parameters. Attackers can craft specific payloads targeting admin pages like server.cfm and web.cfm to execute arbitrary JavaScript in victim's browser sessions.
Metrics
Affected Vendors & Products
References
History
Tue, 16 Dec 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Lucee
Lucee lucee Server |
|
| Vendors & Products |
Lucee
Lucee lucee Server |
Mon, 15 Dec 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 15 Dec 2025 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Lucee 5.4.2.17 contains a reflected cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts through administrative interface parameters. Attackers can craft specific payloads targeting admin pages like server.cfm and web.cfm to execute arbitrary JavaScript in victim's browser sessions. | |
| Title | Lucee 5.4.2.17 Authenticated Reflected Cross-Site Scripting via Admin Interfaces | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2025-12-15T20:28:18.996Z
Updated: 2025-12-15T21:47:26.669Z
Reserved: 2025-12-13T14:25:04.999Z
Link: CVE-2023-53880
Updated: 2025-12-15T21:40:03.408Z
Status : Awaiting Analysis
Published: 2025-12-15T21:15:50.853
Modified: 2025-12-16T14:10:11.300
Link: CVE-2023-53880
No data.