CVE-2025-43955

TwsCachedXPathAPI in Convertigo versions before 8.3.11 did not restrict commons-jxpath functions, which could allow expression injection in contexts where an attacker can influence an evaluated XPath expression. Convertigo 8.3.11 fixes the issue by assigning an empty FunctionLibrary to JXPath contexts.
Configurations

Configuration 1 (hide)

cpe:2.3:a:convertigo:convertigo:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-04-20 20:15

Updated : 2026-08-28 15:51


NVD link : CVE-2025-43955

Mitre link : CVE-2025-43955

CVE.ORG link : CVE-2025-43955


JSON object : View

Products Affected

convertigo

  • convertigo
CWE
CWE-749

Exposed Dangerous Method or Function

CWE-74

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')