Apache

Sling Cms

4 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.16%
  • Veröffentlicht 04.02.2023 21:15:09
  • Zuletzt bearbeitet 25.03.2025 19:15:41

An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability in Sling App CMS version 1.1.4 and prior may allow an authenticated remote attacker to perform a reflected cross-site scripting (XSS) attac...

  • EPSS 0.19%
  • Veröffentlicht 09.01.2023 11:15:10
  • Zuletzt bearbeitet 09.04.2025 20:15:22

An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability in Sling App CMS version 1.1.2 and prior may allow an authenticated remote attacker to perform a reflected cross-site scripting (XSS) attac...

  • EPSS 0.18%
  • Veröffentlicht 02.11.2022 13:15:19
  • Zuletzt bearbeitet 02.05.2025 21:15:22

An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability in Sling App CMS version 1.1.0 and prior may allow an authenticated remote attacker to perform a reflected cross site scripting (XSS) attac...

  • EPSS 1.83%
  • Veröffentlicht 01.04.2020 19:15:14
  • Zuletzt bearbeitet 21.11.2024 05:11:42

Scripts in Sling CMS before 0.16.0 do not property escape the Sling Selector from URLs when generating navigational elements for the administrative consoles and are vulnerable to reflected XSS attacks.