PT-2026-99801 · Apache · Apache Roller
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Apache Roller version 6.1.5
Description
Improper neutralization of input during web page generation leads to stored cross-site scripting (XSS) in the authoring UI. A user with authoring rights can store crafted content that is subsequently written into JavaScript string literals and markup sinks without proper encoding. This allows the stored script to execute in the browser of another author or administrator. This issue affects weblogs with multiple authors or administrators who are not mutually trusted and requires no optional features or non-default configurations.
Recommendations
Upgrade to Apache Roller versions 6.1.6 or later.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Roller