{"id":"GHSA-jj93-4jr5-x45h","summary":"Apache Sling App CMS vulnerable to Cross-site Scripting","details":"A Cross-site Scripting vulnerability in Sling App CMS version 1.1.0 and prior may allow an authenticated remote attacker to perform a reflected cross site scripting (XSS) attack in the taxonomy management feature.","aliases":["CVE-2022-43670"],"modified":"2023-11-01T05:00:15.496161Z","published":"2022-11-02T19:00:31Z","database_specific":{"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2022-11-03T18:12:03Z","nvd_published_at":"2022-11-02T13:15:00Z","cwe_ids":["CWE-79"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-43670"},{"type":"PACKAGE","url":"https://github.com/apache/sling-org-apache-sling-app-cms"},{"type":"WEB","url":"https://lists.apache.org/thread/o68l3l3crfxz107fr9dm74y8vg8kj2cs"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2022/11/02/8"}],"affected":[{"package":{"name":"org.apache.sling:org.apache.sling.cms","ecosystem":"Maven","purl":"pkg:maven/org.apache.sling/org.apache.sling.cms"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.1.2"}]}],"versions":["0.10.0","0.11.0","0.11.2","0.12.0","0.14.0","0.16.0","0.16.2","0.9.0","1.0.2","1.0.4","1.1.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/11/GHSA-jj93-4jr5-x45h/GHSA-jj93-4jr5-x45h.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"}]}