Vulnerability Details CVE-2020-1949
Scripts in Sling CMS before 0.16.0 do not property escape the Sling Selector from URLs when generating navigational elements for the administrative consoles and are vulnerable to reflected XSS attacks.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.018
EPSS Ranking 82.2%
CVSS Severity
CVSS v3 Score 6.1
CVSS v2 Score 4.3
Products affected by CVE-2020-1949
-
cpe:2.3:a:apache:sling_cms:0.10.0
-
cpe:2.3:a:apache:sling_cms:0.11.0
-
cpe:2.3:a:apache:sling_cms:0.11.2
-
cpe:2.3:a:apache:sling_cms:0.12.0
-
cpe:2.3:a:apache:sling_cms:0.14.0