Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Henry Kuijpers

#50847of 53,632
4.3Total CVSS
Vulnerabilities · 1
PT-2015-5993
4.3
2015-06-02
Apache · Apache Sling Servlets Post · CVE-2015-2944
**Name of the Vulnerable Software and Affected Versions** Apache Sling API versions prior to 2.2.2 Apache Sling Servlets Post versions prior to 2.1.2 **Description** The issue allows remote attackers to inject arbitrary web script or HTML via the URI. This is related to the `org/apache/sling/api/servlets/HtmlResponse` and `org/apache/sling/servlets/post/HtmlResponse` components. **Recommendations** For Apache Sling API versions prior to 2.2.2, update to version 2.2.2 or later. For Apache Sling Servlets Post versions prior to 2.1.2, update to version 2.1.2 or later. As a temporary workaround, consider restricting access to the `org/apache/sling/api/servlets/HtmlResponse` and `org/apache/sling/servlets/post/HtmlResponse` components until a patch is available.