CWE-643 XPath表达式中数据转义处理不恰当(XPath注入) 类弱点 11 条 CVE 漏洞汇总,含 AI 中文分析。
CWE-643 指 XPath 注入漏洞,属于数据注入类安全缺陷。当应用程序使用未经验证或转义的外部输入动态构建 XPath 查询时,攻击者可注入恶意代码以篡改查询逻辑,从而绕过身份验证或非法读取敏感数据。开发者应严格对用户输入进行白名单校验,避免直接拼接字符串,并优先使用参数化查询或预编译语句来隔离数据与指令,确保查询结构的完整性。
<users> <user> <login>john</login> <password>abracadabra</password> <home_dir>/home/john</home_dir> </user> <user> <login>cbc</login> <password>1mgr8</password> <home_dir>/home/cbc</home_dir> </user> </users>XPath xpath = XPathFactory.newInstance().newXPath(); XPathExpression xlogin = xpath.compile("//users/user[login/text()='" + login.getUserName() + "' and password/text() = '" + login.getPassword() + "']/home_dir/text()"); Document d = DocumentBuilderFactory.newInstance().newDocumentBuilder().parse(new File("db.xml")); String homedir = xlogin.evaluate(d);| CVE ID | 标题 | CVSS | 风险等级 | Published |
|---|---|---|---|---|
| CVE-2026-24343 | Apache HertzBeat 安全漏洞 — Apache HertzBeat | 9.4AI | CriticalAI | 2026-02-10 |
| CVE-2025-11844 | Hugging Face Transformers 安全漏洞 — huggingface/smolagents | 9.1AI | CriticalAI | 2025-10-22 |
| CVE-2025-20218 | Cisco Secure Firewall Management Center 安全漏洞 — Cisco Firepower Management Center | 4.9 | Medium | 2025-08-14 |
| CVE-2022-43840 | IBM Aspera Console 安全漏洞 — Aspera Console | 4.3 | Medium | 2025-04-14 |
| CVE-2024-39565 | Juniper Networks Junos OS 安全漏洞 — Junos OS | 8.8 | High | 2024-07-10 |
| CVE-2024-2648 | Netentsec NS-ASG Application Security Gateway 安全漏洞 — NS-ASG Application Security Gateway | 4.3 | Medium | 2024-03-19 |
| CVE-2024-2645 | Netentsec NS-ASG Application Security Gateway 安全漏洞 — NS-ASG Application Security Gateway | 4.3 | Medium | 2024-03-19 |
| CVE-2023-36429 | Microsoft Dynamics 365 安全漏洞 — Microsoft Dynamics 365 (on-premises) version 9.0 | 6.5 | Medium | 2023-10-10 |
| CVE-2023-36433 | Microsoft Dynamics 365 安全漏洞 — Microsoft Dynamics 365 (on-premises) version 9.0 | 6.5 | Medium | 2023-10-10 |
| CVE-2023-24922 | Microsoft Dynamics 安全漏洞 — Microsoft Dynamics 365 (on-premises) version 9.0 | 6.5 | Medium | 2023-03-14 |
| CVE-2020-25162 | B. Braun Melsungen Ag B. Braun Melsungen AG SpaceCom 安全漏洞 — SpaceCom | 7.5 | High | 2022-04-14 |
CWE-643(XPath表达式中数据转义处理不恰当(XPath注入)) 是常见的弱点类别,本平台收录该类弱点关联的 11 条 CVE 漏洞。