384
VMScore

CVE-2020-1949

Published: 01/04/2020 Updated: 03/04/2020
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 384
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Scripts in Sling CMS prior to 0.16.0 do not property escape the Sling Selector from URLs when generating navigational elements for the administrative consoles and are vulnerable to reflected XSS attacks.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apache sling cms

Mailing Lists

Severity: Medium Vendor: The Apache Software Foundation Versions Affected: Sling CMS 0140 and previous releases Description: Scripts in Sling CMS do not property escape the Sling Selector from URLs when generating navigational elements for the administrative consoles and are vulnerable to reflected XSS attacks Mitigation: All users should up ...