Impact
An XSS vulnerability exists in the markdown processing of Apache Allura. User‑supplied markdown is not properly neutralized before rendering, allowing an attacker to inject malicious script code that will execute in the victim’s browser.
Affected Systems
All installations of Apache Allura between versions 1.10.0 and 1.19.0 are affected. Applications using any of those releases and allowing users to submit markdown content (e.g., blogs, comments, wikis) are at risk.
Risk and Exploitability
The CVSS score of 6.1 indicates moderate severity. EPSS data is not available. Attackers can exploit the flaw by submitting markdown content that contains malicious scripts, causing the script to execute in the victim’s browser. The vulnerability is not currently listed in the CISA KEV catalog. The primary attack vector is inferred to be malicious markdown input as described by the vendor advisory.
OpenCVE Enrichment