First published: Wed Apr 01 2020(Updated: )
Scripts in Sling CMS before 0.16.0 do not property escape the Sling Selector from URLs when generating navigational elements for the administrative consoles and are vulnerable to reflected XSS attacks.
Credit: security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache Sling Cms | <0.16.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-1949 is classified as a high-severity vulnerability due to its potential for reflected XSS attacks.
To fix CVE-2020-1949, upgrade the Sling CMS to version 0.16.0 or later.
CVE-2020-1949 affects Apache Sling CMS versions prior to 0.16.0.
CVE-2020-1949 is a reflected Cross-Site Scripting (XSS) vulnerability.
Yes, CVE-2020-1949 can be exploited remotely by attackers using crafted URLs.