Impact
Apache Roller versions prior to 6.1.6 allow a stored cross‑site scripting flaw in the authoring UI. The vulnerability arises when user‑supplied content is written directly into JavaScript string literals and markup sinks without proper neutralization. An attacker who has authoring rights can embed malicious script that will execute in the browsers of other authors or administrators, without any configuration change or optional feature. This weakness is classified as CWE‑79.
Affected Systems
The issue affects Apache Software Foundation’s Apache Roller, specifically version 6.1.5. Operators of weblogs running this version should verify the upgrade status and apply the official 6.1.6 update, which rewrites the vulnerable values as plain text rather than embedding them in JavaScript.
Risk and Exploitability
The CVSS score of 5.4 indicates a moderate severity. No exploitation probability data is currently available via EPSS, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is local to the authoring interface; the defect does not require privileged system access and no toggling of settings is necessary. Any user with authoring rights on a shared weblog can target other users, including administrators, by posting crafted content that will run in their browsers when they view the affected page.
OpenCVE Enrichment