Severity: Moderate 
    CVSS 3.1: 6.1 (medium) CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Affected versions:

- Apache Roller 6.1.5

Description:

Improper Neutralization of Input During Web Page Generation ('Cross-site 
Scripting') in Apache Roller 6.1.5 allows an unauthenticated remote attacker to 
store a crafted comment-author URL through the incoming Trackback endpoint when 
a published entry accepts comments and Trackbacks. The shipped Trackback, 
verification and moderation defaults allow the value to be approved and 
rendered as an active link; a visitor who clicks the link executes script in 
the weblog's origin. Users are recommended to upgrade to Apache Roller 6.1.6 or 
later, which removes incoming Trackback support and suppresses non-HTTP(S) 
comment-author links. Users unable to upgrade should disable Trackbacks and 
remove untrusted Trackback comments.

Credit:

m4dn355 (finder)

References:

https://github.com/apache/roller/pull/178
https://roller.apache.org/
https://www.cve.org/CVERecord?id=CVE-2026-82546

Reply via email to