CVE-2020-1949

MEDIUM

Sling CMS < 0.16.0 - Reflected Cross-Site Scripting via Sling Selector

Title source: llm
STIX 2.1

Description

Scripts in Sling CMS before 0.16.0 do not property escape the Sling Selector from URLs when generating navigational elements for the administrative consoles and are vulnerable to reflected XSS attacks.

References (1)

Core 1
Core References
Mailing List, Vendor Advisory x_refsource_misc
https://s.apache.org/CVE-2020-1949

Scores

CVSS v3 6.1
EPSS 0.0183
EPSS Percentile 83.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (1)
apache/sling_cms < 0.16.0
Published Apr 01, 2020
Tracked Since Feb 18, 2026