[CVE-2019-0234] Reflected Cross-site Scripting (XSS) Vulnerabiulity in Apache Roller
Dave <[email protected]> Thu, 11 Jul 2019 18:14:27 -0400
| Newsgroups | gmane.comp.java.roller.user |
|---|---|
| Message-ID | <CAF1aazBk+Xhm03Vaf=m9j6e9wjhFJR+Ras+zL5n7v4ro6xeZgA__38582.7110543445$1562883289$gmane$org@mail.gmail.com> |
Severity: Important Vendor: The Apache Software Foundation Versions affected: Roller 5.2, 5.2.1, 5.2.2. The unsupported pre-Roller 5.1 versions may also be affected. Description: Roller's Math Comment Authenticator did not property sanitize user input and could be exploited to perform Reflected Cross Site Scripting (XSS). Mitigation: The mitigation for this vulnerability is to upgrade to the lastest version of Roller, which is now Roller 5.2.3. Credit: This issue was discovered and reported by Muthukumar Marikani