setAltTable of the file feedGateway.cfc. Such manipulation of the argument altTable leads to sql injection.This vulnerability is referenced as CVE-2026-40331. It is possible to launch the attack remotely. No exploit is available.
It is advisable to upgrade the affected component.