Unrated severityNVD Advisory· Published Apr 1, 2020· Updated Aug 4, 2024
CVE-2020-1949
CVE-2020-1949
Description
Scripts in Sling CMS before 0.16.0 do not property escape the Sling Selector from URLs when generating navigational elements for the administrative consoles and are vulnerable to reflected XSS attacks.
Affected products
2- Sling/Sling CMSdescription
- Range: <0.16.0
Patches
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- s.apache.org/CVE-2020-1949mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.