TwsCachedXPathAPI in Convertigo versions before 8.3.11 did not restrict commons-jxpath functions, which could allow expression injection in contexts where an attacker can influence an evaluated XPath expression. Convertigo 8.3.11 fixes the issue by assigning an empty FunctionLibrary to JXPath contexts.
References
| Link | Resource |
|---|---|
| https://github.com/convertigo/convertigo/blob/8.3.11/CHANGELOG.md#8311 | Release Notes |
| https://github.com/convertigo/convertigo/commit/431d1bfeb360a55f4ed299cc3aa287cc5c6357e1 | Patch |
| https://github.com/convertigo/convertigo/issues/898 | Exploit Issue Tracking |
| https://github.com/convertigo/convertigo/releases/tag/8.3.11 | Release Notes |
Configurations
History
No history.
Information
Published : 2025-04-20 20:15
Updated : 2026-08-28 15:51
NVD link : CVE-2025-43955
Mitre link : CVE-2025-43955
CVE.ORG link : CVE-2025-43955
JSON object : View
Products Affected
convertigo
- convertigo
