Lucene search

K
prionPRIOn knowledge basePRION:CVE-2017-9802
HistoryAug 14, 2017 - 1:29 p.m.

Cross site scripting

2017-08-1413:29:00
PRIOn knowledge base
www.prio-n.com

6.2 Medium

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

62.1%

The Javascript method Sling.evalString() in Apache Sling Servlets Post before 2.3.22 uses the javascript ‘eval’ function to parse input strings, which allows for XSS attacks by passing specially crafted input strings.

CPENameOperatorVersion
sling_servlets_postle2.3.20

6.2 Medium

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

62.1%

Related for PRION:CVE-2017-9802