Context-Inappropriate Capability
High
- Confidence
- 99% confidence
- Finding
- This code enumerates configured ColdFusion datasources, decrypts stored datasource passwords, and prints usernames, passwords, and connection URLs directly to the page. That is explicit credential theft behavior with no legitimate need in the context of a web-facing skill, and it enables immediate database compromise and lateral movement.
