PT-2025-17415 · Unknown · Convertigo+1

Lqxduo

·

Published

2025-04-20

·

Updated

2025-04-20

·

CVE-2025-43955

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Convertigo versions 8.3.4 and earlier
Description The issue is related to the TwsCachedXPathAPI in Convertigo, which does not restrict the use of commons-jxpath APIs.
Recommendations For versions 8.3.4 and earlier, consider restricting access to the TwsCachedXPathAPI until a patch is available. As a temporary workaround, consider disabling the use of commons-jxpath APIs in the TwsCachedXPathAPI to minimize the risk of exploitation.

Exploit

Fix

Special Elements Injection

Weakness Enumeration

Related Identifiers

CVE-2025-43955

Affected Products

Convertigo
Commons-Jxpath