Lucene search

K

Sling Xss Protection Api Security Vulnerabilities

cve
cve

CVE-2017-15717

A flaw in the way URLs are escaped and encoded in the org.apache.sling.xss.impl.XSSAPIImpl#getValidHref and org.apache.sling.xss.impl.XSSFilterImpl#isValidHref allows special crafted URLs to pass as valid, although they carry XSS payloads. The affected versions are Apache Sling XSS Protection API 1...

6.1CVSS

5.8AI Score

0.002EPSS

2018-01-10 02:29 PM
51