First published: Wed Apr 01 2020(Updated: )
Scripts in Sling CMS before 0.16.0 do not property escape the Sling Selector from URLs when generating navigational elements for the administrative consoles and are vulnerable to reflected XSS attacks.
Credit: security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache Sling Cms | <0.16.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.