CVE-2016-6798

Severity
9.8CRITICAL
EPSS
1.3%
top 19.96%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 19
Latest updateMay 17

Description

In the XSS Protection API module before 1.0.12 in Apache Sling, the method XSS.getValidXML() uses an insecure SAX parser to validate the input string, which allows for XXE attacks in all scripts which use this method to validate user input, potentially allowing an attacker to read sensitive data on the filesystem, perform same-site-request-forgery (SSRF), port-scanning behind the firewall or DoS the application.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages4 packages

🔴Vulnerability Details

3
OSV
XML External Entity Reference in Apache Sling2022-05-17
GHSA
XML External Entity Reference in Apache Sling2022-05-17
CVEList
CVE-2016-6798: In the XSS Protection API module before 12017-07-19
CVE-2016-6798 (CRITICAL CVSS 9.8) | In the XSS Protection API module be | cvebase.io