PT-2026-99789 · Apache · Apache Roller
CVSS v3.1
7.7
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Apache Roller version 6.1.5
Description
Improper restriction of XML External Entity (XXE) references allows a user with entry-editing rights on a weblog to force the server to parse a trackback response using an XML parser that does not disable external entity resolution. This can lead to the disclosure of files readable by the Roller process. Although the Trackback control is hidden in the standard UI, the action remains directly reachable without requiring any non-default server configuration.
Recommendations
Upgrade to Apache Roller version 6.1.6 or later.
Fix
XXE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Roller