Impact
The vulnerability is an improper neutralization of input during web page generation, which allows an attacker to inject malicious scripts into pages served by the XSS Webconsole plugin. If exploited, the attacker can execute arbitrary client‑side code against users who view the web console, potentially leading to session hijacking, credential theft or unauthorized actions within the browser context.
Affected Systems
Apache Sling XSS deployments with a version earlier than 2.4.12, as identified by the Apache Software Foundation.
Risk and Exploitability
The EPSS score is reported to be less than 1 % and the vulnerability is not listed in the CISA KEV catalog, indicating a low probability of publicly observed exploitation. The CVSS score of 6.1 classifies this issue as moderate severity, and the attack likely requires the ability to send crafted input to the web console; it is therefore considered a moderate‑severity issue in terms of potential impact, but with a low exploitation likelihood based on the current data.
OpenCVE Enrichment