Lucene search

K
cvelistApacheCVELIST:CVE-2022-43670
HistoryNov 02, 2022 - 12:00 a.m.

CVE-2022-43670 XSS in Sling CMS Reference App Taxonomy Path

2022-11-0200:00:00
CWE-79
apache
www.cve.org
sling cms
cross-site scripting
taxonomy management

0.001 Low

EPSS

Percentile

30.3%

An improper neutralization of input during web page generation (‘Cross-site Scripting’) [CWE-79] vulnerability in Sling App CMS version 1.1.0 and prior may allow an authenticated remote attacker to perform a reflected cross site scripting (XSS) attack in the taxonomy management feature.

CNA Affected

[
  {
    "vendor": "Apache Software Foundation",
    "product": "Apache Sling App CMS",
    "versions": [
      {
        "version": "unspecified",
        "lessThan": "1.1.2",
        "status": "affected",
        "versionType": "custom"
      }
    ]
  }
]

0.001 Low

EPSS

Percentile

30.3%

Related for CVELIST:CVE-2022-43670