PT-2026-47712 · Apache · Apache Answer
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Apache Answer versions prior to 2.0.1
Description
Improper Neutralization of Alternate XSS Syntax occurs when AI-generated response content is rendered in the browser without proper sanitization. This allows malicious scripts to be executed when the content is viewed. Cross-Site Scripting (XSS) is a flaw where an attacker injects malicious scripts into content delivered to other users.
Recommendations
Upgrade to version 2.0.1.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Answer