vendor:
Concrete5 CME
by:
nu11secur1ty
7.5
CVSS
HIGH
Xpath injection
CWE
Product Name: Concrete5 CME
Affected Version From: 9.1.2003
Affected Version To: 9.1.2003
Patch Exists:
Related CWE:
CPE:
Platforms Tested:
2022
Concrete5 CME v9.1.3 – Xpath injection
The URL path folder `3` appears to be vulnerable to XPath injection attacks. The test payload 50539478' or 4591=4591-- was submitted in the URL path folder `3`, and an XPath error message was returned. The attacker can flood with requests the system by using this vulnerability to untilted he receives the actual paths of the all content of this system which content is stored on some internal or external server.