CVE-2015-2944

Description

Multiple cross-site scripting (XSS) vulnerabilities in Apache Sling API before 2.2.2 and Apache Sling Servlets Post before 2.1.2 allow remote attackers to inject arbitrary web script or HTML via the URI, related to (1) org/apache/sling/api/servlets/HtmlResponse and (2) org/apache/sling/servlets/post/HtmlResponse.

Risk Information

Base Score
9.8
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C
EPSS Score
Exploitation Probability
2.866

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2012-2138,CVE-2015-2944 are fixed in Apache-org.apache.sling.servlets.post 2.1.2Windows
Vulnerabilities CVE-2015-2944 are fixed in Apache-org.apache.sling.api 2.2.2Windows
Vulnerabilities CVE-2012-2138,CVE-2015-2944 are fixed in Apache-org.apache.sling.servlets.post for Linux 2.1.2Linux
Vulnerabilities CVE-2015-2944 are fixed in Apache-org.apache.sling.api for Linux 2.2.2Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234