Impact
The vulnerability arises from a failure to properly neutralize user‑supplied input during the rendering of web pages, allowing malicious scripts to be injected. This cross‑site scripting flaw can enable attackers to run arbitrary code in victims’ browsers, potentially leading to session hijacking, data theft, or defacement. The associated sanitizer bypass and uncontrolled resource consumption highlighted in the advisory also suggest that attackers might trigger excessive processing or disable protection mechanisms, amplifying the risk.
Affected Systems
Apache Sling XSS components released by the Apache Software Foundation before version 2.4.12 are affected. Systems running any earlier version of this product are vulnerable until the 2.4.12 update is applied.
Risk and Exploitability
The EPSS score is below 1 %, indicating a low probability of active exploitation at the time of analysis, and the vulnerability is not listed in the CISA KEV catalog. Likely attack vectors involve HTTP requests that include malicious payloads in web request parameters or form data. Because the flaw is client‑side and requires a browser to process the injected content, it is particularly dangerous for users who access the affected pages without stringent browser or network controls. Still, the limited exploitation probability and lack of critical effort in known attacks imply a moderate overall risk, but the potential for resource exhaustion means that even low‑volume attacks could degrade service availability. The CVSS score of 6.1 indicates medium severity.
OpenCVE Enrichment