{"id":"GHSA-38m2-vr6g-8c94","summary":"Apache Sling App CMS vulnerable to reflected Cross-site Scripting","details":"An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability in Sling App CMS version 1.1.2 and prior may allow an authenticated remote attacker to perform a reflected cross-site scripting (XSS) attack in the site group feature. Upgrade to Apache Sling App CMS \u003e= 1.1.4","aliases":["CVE-2022-46769"],"modified":"2023-11-08T04:10:57.774496Z","published":"2023-01-09T12:30:18Z","database_specific":{"cwe_ids":["CWE-79"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2023-01-09T21:58:35Z","nvd_published_at":"2023-01-09T11:15:00Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-46769"},{"type":"PACKAGE","url":"https://github.com/apache/sling-org-apache-sling-app-cms"},{"type":"WEB","url":"https://sling.apache.org/news.html"}],"affected":[{"package":{"name":"org.apache.sling:org.apache.sling.cms","ecosystem":"Maven","purl":"pkg:maven/org.apache.sling/org.apache.sling.cms"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.1.4"}]}],"versions":["0.10.0","0.11.0","0.11.2","0.12.0","0.14.0","0.16.0","0.16.2","0.9.0","1.0.2","1.0.4","1.1.0","1.1.2"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/01/GHSA-38m2-vr6g-8c94/GHSA-38m2-vr6g-8c94.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"}]}