CyberRota Analysis
AI-GeneratedApache Sling XSS versions 2.4.10 and earlier are vulnerable to reflected cross-site scripting (XSS) due to improper input neutralization in the XSSAPI.getValidHref() method. This flaw allows attackers to inject malicious scripts if they can submit unsanitized values, potentially compromising user sessions or stealing sensitive information. Organizations using affected versions should prioritize upgrading to Apache Sling XSS version 2.4.12 or later to mitigate this risk.
Original NVD Description
An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability when using the XSSAPI.getValidHref() in Apache Sling XSS version 2.4.10 and prior may allow an attacker to perform a reflected cross-site scripting (XSS) attack in every feature using this method. In order to successfully attack an application, the attacker needs to be able to submit a value which is not correctly sanitized by that library. Upgrade to Apache Sling XSS >= 2.4.12
Related CVEs
Other vulnerabilities affecting the same vendor(s)