VYPR
Medium severity5.9NVD Advisory· Published Feb 14, 2023· Updated Jun 17, 2026

CVE-2023-23835

CVE-2023-23835

Description

A vulnerability has been identified in Mendix Applications using Mendix 7 (All versions < V7.23.34), Mendix Applications using Mendix 8 (All versions < V8.18.23), Mendix Applications using Mendix 9 (All versions < V9.22.0), Mendix Applications using Mendix 9 (V9.12) (All versions < V9.12.10), Mendix Applications using Mendix 9 (V9.18) (All versions < V9.18.4), Mendix Applications using Mendix 9 (V9.6) (All versions < V9.6.15). Some of the Mendix runtime API’s allow attackers to bypass XPath constraints and retrieve information using XPath queries that trigger errors.

Affected products

8
  • cpe:2.3:a:mendix:mendix:*:*:*:*:*:*:*:*
    Range: >=7.0.2,<7.23.34
  • All versions < V7.23.34+ 5 more
    • (no CPE)range: All versions < V7.23.34
    • (no CPE)range: All versions < V8.18.23
    • (no CPE)range: All versions < V9.22.0
    • (no CPE)range: All versions < V9.12.10
    • (no CPE)range: All versions < V9.18.4
    • (no CPE)range: All versions < V9.6.15

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.