2.2lowLow
CVE-2025-43955
Convertigo Convertigo
TwsCachedXPathAPI in Convertigo versions before 8.3.11 did not restrict commons-jxpath functions, which could allow expression injection in contexts where an attacker can influence an evaluated XPath expression. Convertigo 8.3.11 fixes the issue by assigning an empty FunctionLibrary to JXPath contexts.
Exploitation status
- Published references include exploit or proof-of-concept material. There is no confirmation it is being used in real attacks.
- A vendor advisory or patch reference has been published.
What the metrics mean
- It is requires local access to the machine.
- For an attacker who can reach it, exploitation depends on conditions outside the attacker's control.
- To exploit it, an ordinary user account is needed.
- Beyond that, someone has to be persuaded to take an action first.
Scoring
- CVSS
- 2.2 (v3.1)
- Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:L/A:N- Weakness
- CWE-749
- Assigned by
- cve@mitre.org
Dates
- Published
- 2025-04-20
- Last modified
- 2026-08-28
- Sources
- NVD
Affected products
- Convertigo Convertigo- 8.3.11
As listed in the NVD configuration data. Not a statement about your estate.