Vulnerabilities > Ortussolutions

DATE CVE VULNERABILITY TITLE RISK
2023-11-06 CVE-2021-4430 Unspecified vulnerability in Ortussolutions Coldbox Elixir 3.1.6
A vulnerability classified as problematic has been found in Ortus Solutions ColdBox Elixir 3.1.6.
network
low complexity
ortussolutions
7.5
2020-11-24 CVE-2020-15929 Command Injection vulnerability in Ortussolutions Testbox
In Ortus TestBox 2.4.0 through 4.1.0, unvalidated query string parameters passed to system/runners/HTMLRunner.cfm allow an attacker to write an arbitrary CFM file (within the application's context) containing attacker-defined CFML tags, leading to Remote Code Execution.
network
low complexity
ortussolutions CWE-77
7.5
2020-11-24 CVE-2020-15928 Path Traversal vulnerability in Ortussolutions Testbox
In Ortus TestBox 2.4.0 through 4.1.0, unvalidated query string parameters to test-browser/index.cfm allow directory traversal.
network
low complexity
ortussolutions CWE-22
5.0