Cross-site Scripting Vulnerability in Apache Sling XSS by Apache
CVE-2026-73192
Currently unrated
What is CVE-2026-73192?
This vulnerability arises due to improper handling of user input during web page generation, allowing an attacker to execute a reflected Cross-site Scripting (XSS) attack through the XSSAPI.getValidHref() method. If the attacker submits a value that is inadequately sanitized, they can manipulate the application and potentially compromise security across various functionalities. The issue is present in Apache Sling XSS version 2.4.10 and earlier. Users are advised to upgrade to version 2.4.12 or later to mitigate the risk.
Affected Version(s)
Apache Sling XSS 0 < 2.4.12