GHSA-xg59-jgm4-xmq5MediumCVSS 6.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Apache...

Published
September 28, 2026
Last Modified
September 28, 2026

🔗 CVE IDs covered (1)

📋 Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Apache Roller 6.1.5 allows an anonymous remote attacker to store a comment containing a javascript: URI link that survives HTML comment formatting and can execute script in the browser of a visitor who clicks it. This affects only sites that enable HTML in comments (users.comments.htmlenabled=true) together with the HTMLSubset comment formatter; comment moderation, where enabled, delays publication. Users are recommended to upgrade to Apache Roller 6.1.6 or later, which restricts restored links to http, https and mailto URIs.

🔗 References (5)