First published: Sat Aug 05 2023(Updated: )
Insufficient input validation and sanitation in Weblog Category name, Website About and File Upload features in all versions of Apache Roller on all platforms allows an authenticated user to perform an XSS attack. Mitigation: if you do not have Roller configured for untrusted users, then you need to do nothing because you trust your users to author raw HTML and other web content. If you are running with untrusted users then you should upgrade to Roller 6.1.2 and you should disable Roller's File Upload feature.
Credit: security@apache.org security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache Roller | <6.1.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-37581 is an XSS vulnerability in Apache Roller that affects all versions of the software.
CVE-2023-37581 has a severity rating of medium with a CVSS score of 5.4.
The CWE ID for CVE-2023-37581 is CWE-79 and CWE-20.
To mitigate CVE-2023-37581, ensure that Apache Roller is not configured for untrusted users.
You can find more information about CVE-2023-37581 on the Apache mailing list and security forums.