Concrete5 CMS version 9.1.3 contains an XPath injection vulnerability that allows attackers to manipulate URL path parameters with malicious payloads. Attackers can flood the system with crafted requests to potentially extract internal content paths and system information.
Metrics
Affected Vendors & Products
References
History
Tue, 13 Jan 2026 23:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Concrete5 CMS version 9.1.3 contains an XPath injection vulnerability that allows attackers to manipulate URL path parameters with malicious payloads. Attackers can flood the system with crafted requests to potentially extract internal content paths and system information. | |
| Title | Concrete5 CME 9.1.3 - Xpath injection | |
| Weaknesses | CWE-643 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-01-13T22:51:40.976Z
Reserved: 2025-12-27T13:53:29.756Z
Link: CVE-2022-50807
No data.
Status : Received
Published: 2026-01-13T23:15:50.003
Modified: 2026-01-13T23:15:50.003
Link: CVE-2022-50807
No data.
OpenCVE Enrichment
No data.