Executive brief
Apache Sling XSS is a library that sanitizes user input to prevent cross-site scripting attacks in web applications. A flaw in the getValidHref() method fails to properly neutralize malicious input, allowing an attacker to inject and execute arbitrary JavaScript code in a user's browser when the library is used in an application. An attacker needs to submit an unsanitized value through an application that uses this vulnerable method to exploit the flaw.
Technical details
The vulnerability is an improper input neutralization (CWE-79) in the XSSAPI.getValidHref() method that permits reflected XSS attacks. The flaw requires attacker-controlled input to be passed to the vulnerable method without additional sanitization by the consuming application. The issue is resolved in Apache Sling XSS version 2.4.12 and later.
Affected products
- Apache Sling XSS 2.4.10 and prior
Timeline
- 2026-09-23: disclosed