CVE-2022-50807: Concrete5 CME 9.1.3 - Xpath injection
Concrete5 CMS version 9.1.3 contains an XPath injection vulnerability that allows attackers to manipulate URL path parameters with malicious payloads. Attackers can flood the system with crafted requests to potentially extract internal content paths and system information.
Other sources
Rejected reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue.
— NVD
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-50807?
CVE-2022-50807 is classified as a medium-severity vulnerability due to its potential for XPath injection.
How do I fix CVE-2022-50807?
To fix CVE-2022-50807, update your Concrete5 CMS to the latest version that addresses this XPath injection vulnerability.
What are the potential impacts of CVE-2022-50807?
The potential impacts of CVE-2022-50807 include unauthorized access to internal content paths and information disclosure.
Who is affected by CVE-2022-50807?
CVE-2022-50807 affects users of Concrete5 CMS version 9.1.3 and possibly earlier versions.
Is there a proof of concept for CVE-2022-50807?
Yes, there is a proof of concept available that demonstrates the XPath injection exploit in CVE-2022-50807.