VYPR

Sling XSS Protection API

by Apache

Source repositories

CVEs (1)

  • CVE-2017-15717MedJan 10, 2018
    risk 0.40cvss 6.1epss 0.03

    A flaw in the way URLs are escaped and encoded in the org.apache.sling.xss.impl.XSSAPIImpl#getValidHref and org.apache.sling.xss.impl.XSSFilterImpl#isValidHref allows special crafted URLs to pass as valid, although they carry XSS payloads. The affected versions are Apache Sling…