First published: Mon Jul 15 2019(Updated: )
A Reflected Cross-site Scripting (XSS) vulnerability exists in Apache Roller. Roller's Math Comment Authenticator did not property sanitize user input and could be exploited to perform Reflected Cross Site Scripting (XSS). The mitigation for this vulnerability is to upgrade to the latest version of Roller, which is now Roller 5.2.3.
Credit: security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache Roller | =5.2.0 | |
Apache Roller | =5.2.1 | |
Apache Roller | =5.2.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-0234 is a Reflected Cross-site Scripting (XSS) vulnerability in Apache Roller.
The severity of CVE-2019-0234 is medium with a CVSS score of 6.1.
CVE-2019-0234 affects Apache Roller versions 5.2.0, 5.2.1, and 5.2.2.
To mitigate CVE-2019-0234, upgrade Apache Roller to the latest version.
CVE-2019-0234 is classified under CWE-79 (Improper Neutralization of Input During Web Page Generation).