6.8
CVE-2025-43955
- EPSS 0.24%
- Veröffentlicht 20.04.2025 00:00:00
- Zuletzt bearbeitet 28.08.2026 15:51:06
- Erkennungen
TwsCachedXPathAPI in Convertigo versions before 8.3.11 did not restrict commons-jxpath functions, which could allow expression injection in contexts where an attacker can influence an evaluated XPath expression. Convertigo 8.3.11 fixes the issue by assigning an empty FunctionLibrary to JXPath contexts.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Convertigo ≫ Convertigo Version < 8.3.11
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.24% | 0.151 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 6.8 | 0.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H
|
| MITRE | 2.2 | 0.8 | 1.4 |
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:L/A:N
|
CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.
CWE-749 Exposed Dangerous Method or Function
The product provides an Applications Programming Interface (API) or similar interface for interaction with external actors, but the interface includes a dangerous method or function that is not properly restricted.
https://github.com/convertigo/convertigo/issues/898
https://github.com/convertigo/convertigo/blob/8.3.11/CHANGELOG.md#8311
https://github.com/convertigo/convertigo/commit/431d1bfeb360a55f4ed299cc3aa287cc5c6357e1
https://github.com/convertigo/convertigo/releases/tag/8.3.11