Skip to main content

Vendor/product archive

apache / sling_servlets_post CVEs

Beta · best-effort

2 CVEs tagged to apache / sling_servlets_post0 Critical, 0 High, 2 Medium, 0 Low, 0 Unrated.

CVE-2017-9802

Published Aug 14, 2017

The Javascript method Sling.evalString() in Apache Sling Servlets Post before 2.3.22 uses the javascript 'eval' function to parse input strings, which allows for XSS attacks by pa…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-2 of 2 CVEsPage 1 of 1