Executive brief
Apache Sling XSS is a library used to prevent cross-site scripting attacks in web applications. A cross-site scripting vulnerability in the web console plugin allows attackers to inject malicious scripts that execute in users' browsers, potentially stealing session tokens, credentials, or sensitive data. Users should upgrade to version 2.4.12 to resolve the issue.
Technical details
An improper input neutralization vulnerability in the Apache Sling XSS web console plugin allows reflected or stored cross-site scripting (XSS) attacks. The vulnerability stems from inadequate escaping of user-supplied input during HTML generation. An attacker can craft malicious input that bypasses XSS protections, executing arbitrary JavaScript in the context of a victim's browser session.
Affected products
- Apache Sling XSS before 2.4.12
Timeline
- 2026-09-23: disclosed