Description
An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability in Sling App CMS version 1.1.2 and prior may allow an authenticated remote attacker to perform a reflected cross-site scripting (XSS) attack in the site group feature. Upgrade to Apache Sling App CMS >= 1.1.4
Remediation
References
https://sling.apache.org/news.html
Related Vulnerabilities
CVE-2021-21622 Vulnerability in maven package io.jenkins.plugins:artifact-repository-parameter
CVE-2020-24554 Vulnerability in maven package com.liferay.release.portal.bom
CVE-2019-12421 Vulnerability in maven package org.apache.nifi:nifi-nar-bundles
CVE-2022-34169 Vulnerability in maven package xalan:xalan
CVE-2019-12423 Vulnerability in maven package org.apache.cxf:cxf-rt-rs-security-jose