CVE-2020-1949
01.04.2020, 19:15
Scripts in Sling CMS before 0.16.0 do not property escape the Sling Selector from URLs when generating navigational elements for the administrative consoles and are vulnerable to reflected XSS attacks.
| Vendor | Product | Version |
|---|---|---|
| apache | sling_cms | 𝑥 < 0.16.0 |
𝑥
= Vulnerable software versions