3 results (0.005 seconds)

CVSS: 9.0EPSS: 1%CPEs: 1EXPL: 0

13 Apr 2023 — The SlingRequestDispatcher doesn't correctly implement the RequestDispatcher API resulting in a generic type of include-based cross-site scripting issues on the Apache Sling level. The vulnerability is exploitable by an attacker that is able to include a resource with specific content-type and control the include path (i.e. writing content). The impact of a successful attack is privilege escalation to administrative power. Please update to Apache Sling Engine >= 2.14.0 and enable the "Check Content-Type ove... • http://www.openwall.com/lists/oss-security/2023/04/18/6 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 9.8EPSS: 1%CPEs: 1EXPL: 1

19 Jul 2017 — In the XSS Protection API module before 1.0.12 in Apache Sling, the method XSS.getValidXML() uses an insecure SAX parser to validate the input string, which allows for XXE attacks in all scripts which use this method to validate user input, potentially allowing an attacker to read sensitive data on the filesystem, perform same-site-request-forgery (SSRF), port-scanning behind the firewall or DoS the application. En el módulo de la API de protección XSS anterior a la versión 1.0.12 en Apache Sling, el método... • https://github.com/tafamace/CVE-2016-6798 • CWE-611: Improper Restriction of XML External Entity Reference •

CVSS: 6.1EPSS: 1%CPEs: 1EXPL: 1

19 Jul 2017 — In the XSS Protection API module before 1.0.12 in Apache Sling, the encoding done by the XSSAPI.encodeForJSString() method is not restrictive enough and for some input patterns allows script tags to pass through unencoded, leading to potential XSS vulnerabilities. En el módulo de la API de protección XSS anterior a la versión 1.0.12 en Apache Sling, la codificación hecha por el método de la función XSSAPI.encodeForJSString() no es lo suficientemente restrictiva y, para algunos patrones de entrada, permite q... • https://github.com/epicosy/VUL4J-23 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •