Impact
Apache Roller version 6.1.5 contains a flaw that improperly neutralizes user input during web page generation. The bundled frontpage theme reflects the value of the blog‑directory parameter without proper escaping, allowing an attacker to embed arbitrary JavaScript in a crafted URL. If a victim follows the malicious link, the script runs in the victim’s browser, creating a reflected cross‑site scripting vulnerability identified as CWE‑79.
Affected Systems
The vulnerability affects deployments of Apache Roller 6.1.5 that use the bundled frontpage theme. No other themes or product versions are affected. Users should verify that they are running version 6.1.5 or a vulnerable earlier release and that the frontpage theme is active. Version 6.1.6 or later includes validation and contextual escaping and is not vulnerable.
Risk and Exploitability
The CVSS score of 6.1 indicates moderate severity. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires only a crafted URL that a victim must click; no authentication or privileged access is needed. The risk is therefore confined to users who open malicious links, making it a low‑to‑moderate threat under typical conditions.
OpenCVE Enrichment