This Metasploit module exploits an Improper Access Vulnerability in Adobe Coldfusion versions prior to version 2023 Update 6 and 2021 Update 12. The vulnerability allows unauthenticated attackers to request authentication token in the form of a UUID from the /CFIDE/adminapi/_servermanager/servermanager.cfc endpoint. Using that UUID attackers can hit the /pms endpoint in order to exploit the Arbitrary File Read Vulnerability.
e89b9c55f15b5bbc361d35004fa9ae593f647615c4b1b4703a7b67d828ea9ff3