{"id":"GHSA-rghh-ghf7-7943","summary":"Sling App CMS Cross-site Scripting vulnerability","details":"An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability in Sling App CMS version 1.1.4 and prior may allow an authenticated remote attacker to perform a reflected cross-site scripting (XSS) attack in multiple features. Upgrade to Apache Sling App CMS \u003e= 1.1.6","aliases":["CVE-2023-22849"],"modified":"2023-11-08T04:11:38.979169Z","published":"2023-02-04T21:30:22Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2023-02-08T21:31:51Z","nvd_published_at":"2023-02-04T21:15:00Z","cwe_ids":["CWE-79"],"severity":"MODERATE"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-22849"},{"type":"WEB","url":"https://sling.apache.org/news.html"}],"affected":[{"package":{"name":"org.apache.sling:org.apache.sling.cms","ecosystem":"Maven","purl":"pkg:maven/org.apache.sling/org.apache.sling.cms"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.1.6"}]}],"versions":["0.10.0","0.11.0","0.11.2","0.12.0","0.14.0","0.16.0","0.16.2","0.9.0","1.0.2","1.0.4","1.1.0","1.1.2","1.1.4"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/02/GHSA-rghh-ghf7-7943/GHSA-rghh-ghf7-7943.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}