Executive brief
Apache Sling XSS is a web application library that protects against malicious scripts in user-generated content. A cross-site scripting (XSS) vulnerability in versions before 2.4.12 allows attackers to bypass sanitization protections and inject malicious scripts into web pages, potentially leading to session hijacking, credential theft, or malware distribution to users viewing affected pages.
Technical details
This is an improper input neutralization vulnerability in Apache Sling XSS that allows bypass of XSS protections through unsanitized user input during web page generation. The vulnerability affects versions before 2.4.12 and can be exploited via network access with no authentication required if the affected application processes untrusted input. Exploitation allows an attacker to execute arbitrary JavaScript in the context of affected users' browsers; the issue is resolved in version 2.4.12.
Affected products
- Apache Sling XSS before 2.4.12
Timeline
- 2026-09-23: disclosed