Withdrawn: ConcreteCMS vulnerable to Xpath injection attacks
High severity
GitHub Reviewed
Published
Dec 6, 2022
to the GitHub Advisory Database
•
Updated Jun 6, 2023
Withdrawn
This advisory was withdrawn on Jun 6, 2023
Description
Published by the National Vulnerability Database
Dec 5, 2022
Published to the GitHub Advisory Database
Dec 6, 2022
Reviewed
Dec 6, 2022
Withdrawn
Jun 6, 2023
Last updated
Jun 6, 2023
Withdrawn
This advisory has been withdrawn because it has been found not to be a security issue and withdrawn by its CNA. Please see the message from NVD here for more information. This link is maintained to preserve external references.
Original Description
ConcreteCMS v9.1.3 was discovered to be vulnerable to Xpath injection attacks. This vulnerability allows attackers to access sensitive XML data via a crafted payload injected into the URL path folder "3".
References