XSS Vulnerability in Apache Sling XSS Protection API
CVE-2017-15717
6.1MEDIUM
What is CVE-2017-15717?
A security flaw in the Apache Sling XSS Protection API allows specially crafted URLs to erroneously bypass validation checks. This vulnerability affects versions 1.0.4 through 1.0.18 of the API and enables malicious links containing XSS payloads to be treated as valid. Attackers can exploit this weakness to execute unauthorized scripts in the browser of unsuspecting users, compromising the integrity and security of web applications.
Affected Version(s)
Apache Sling XSS Protection API 1.0.4 to 1.0.18
Apache Sling XSS Protection API Compat 1.1.0
Apache Sling XSS Protection API 2.0.0