TwsCachedXPathAPI in Convertigo versions before 8.3.11 did not restrict commons-jxpath functions, which could allow expression injection in contexts where an attacker can influence an evaluated XPath expression. Convertigo 8.3.11 fixes the issue by assigning an empty FunctionLibrary to JXPath contexts.
Metrics
Affected Vendors & Products
References
History
Wed, 26 Aug 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | TwsCachedXPathAPI in Convertigo through 8.3.4 does not restrict the use of commons-jxpath APIs. | TwsCachedXPathAPI in Convertigo versions before 8.3.11 did not restrict commons-jxpath functions, which could allow expression injection in contexts where an attacker can influence an evaluated XPath expression. Convertigo 8.3.11 fixes the issue by assigning an empty FunctionLibrary to JXPath contexts. |
| References |
|
Tue, 13 May 2025 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Convertigo
Convertigo convertigo |
|
| Weaknesses | CWE-74 | |
| CPEs | cpe:2.3:a:convertigo:convertigo:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Convertigo
Convertigo convertigo |
Mon, 21 Apr 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sun, 20 Apr 2025 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-749 | |
| Metrics |
cvssV3_1
|
Sun, 20 Apr 2025 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | TwsCachedXPathAPI in Convertigo through 8.3.4 does not restrict the use of commons-jxpath APIs. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published: 2025-04-20T00:00:00.000Z
Updated: 2026-08-26T15:50:32.239Z
Reserved: 2025-04-20T00:00:00.000Z
Link: CVE-2025-43955
Updated: 2025-04-21T13:30:23.680Z
Status : Analyzed
Published: 2025-04-20T20:15:13.553
Modified: 2026-08-28T15:51:06.993
Link: CVE-2025-43955
No data.