CVE-2022-46464

ConcreteCMS v9.1.3 was discovered to be vulnerable to Xpath injection attacks. This vulnerability allows attackers to access sensitive XML data via a crafted payload injected into the URL path folder "3".
Configurations

Configuration 1

cpe:2.3:a:concretecms:concrete_cms:9.1.3:*:*:*:*:*:*:*

Information

Published : 2022-12-05 11:15

Updated : 2022-12-06 08:04


NVD link : CVE-2022-46464

Mitre link : CVE-2022-46464

Products Affected
No products.
CWE