Security Advisory

CVE-2020-1949

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2020-04-01 18:25:32
Last updated 2024-08-04 06:53:59
Assigner apache
State PUBLISHED

Description

Scripts in Sling CMS before 0.16.0 do not property escape the Sling Selector from URLs when generating navigational elements for the administrative consoles and are vulnerable to reflected XSS attacks.