ZeroHour

CVE-2020-1949

CVSS 3.1
6.1 medium
EPSS
2%p79
Published
()
Modified
Description

Scripts in Sling CMS before 0.16.0 do not property escape the Sling Selector from URLs when generating navigational elements for the administrative consoles and are vulnerable to reflected XSS attacks.

Vendors
apache
Products
sling cms
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.