{"id":"CVE-2022-43670","summary":"XSS in Sling CMS Reference App Taxonomy Path","details":"An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability in Sling App CMS version 1.1.0 and prior may allow an authenticated remote attacker to perform a reflected cross site scripting (XSS) attack in the taxonomy management feature.","aliases":["GHSA-jj93-4jr5-x45h"],"modified":"2026-08-12T03:51:36.294797581Z","published":"2022-11-02T00:00:00Z","database_specific":{"unresolved_ranges":[{"extracted_events":[{"fixed":"1.1.2"}],"source":"AFFECTED_FIELD"}],"cna_assigner":"apache","cwe_ids":["CWE-79"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/43xxx/CVE-2022-43670.json"},"references":[{"type":"WEB","url":"https://lists.apache.org/thread/o68l3l3crfxz107fr9dm74y8vg8kj2cs"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/43xxx/CVE-2022-43670.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-43670"},{"type":"ARTICLE","url":"http://www.openwall.com/lists/oss-security/2022/11/02/8"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/apache/sling-org-apache-sling-app-cms","events":[{"introduced":"0"},{"last_affected":"842104827ee6ee9e7c38bee9a6ca56d5e464a806"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"last_affected":"1.1.0"}],"source":"CPE_RANGE","cpe":"cpe:2.3:a:apache:sling_cms:*:*:*:*:*:*:*:*"}}],"versions":["org.apache.sling.cms-1.1.0","org.apache.sling.cms-1.0.4","org.apache.sling.cms-1.0.2","org.apache.sling.cms-0.16.2","org.apache.sling.cms-0.16.0","org.apache.sling.cms-0.14.0","org.apache.sling.cms-0.12.0","org.apache.sling.cms-0.11.0","org.apache.sling.cms-0.10.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-43670.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"}]}