Home
LOW: 2.2 CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:L/A:NDefault status
unknown
Any version
affected
Description
TwsCachedXPathAPI in Convertigo through 8.3.4 does not restrict the use of commons-jxpath APIs.
Problem types
CWE-749 Exposed Dangerous Method or Function
Product status
Any version
References
github.com/convertigo/convertigo/issues/898