CVE-2025-43955
2.2
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:L/A:N
Summary
TwsCachedXPathAPI in Convertigo versions before 8.3.11 did not restrict commons-jxpath functions, which could allow expression injection in contexts where an attacker can influence an evaluated XPath expression. Convertigo 8.3.11 fixes the issue by assigning an empty FunctionLibrary to JXPath contexts.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Convertigo | Convertigo | 0 <= 8.3.4 | affected |
Weaknesses
- CWE-749: CWE-749 Exposed Dangerous Method or Function
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: no
- Technical Impact: partial
References
- https://github.com/convertigo/convertigo/issues/898
- https://github.com/convertigo/convertigo/commit/431d1bfeb360a55f4ed299cc3aa287cc5c6357e1
- https://github.com/convertigo/convertigo/blob/8.3.11/CHANGELOG.md#8311
- https://github.com/convertigo/convertigo/releases/tag/8.3.11
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.