Vulnerabilities > Apache > Sling > Critical

DATE CVE VULNERABILITY TITLE RISK
2023-04-13 CVE-2022-45064 Cross-site Scripting vulnerability in Apache Sling
The SlingRequestDispatcher doesn't correctly implement the RequestDispatcher API resulting in a generic type of include-based cross-site scripting issues on the Apache Sling level.
network
low complexity
apache CWE-79
critical
9.0
2017-07-19 CVE-2016-6798 XXE vulnerability in Apache Sling
In the XSS Protection API module before 1.0.12 in Apache Sling, the method XSS.getValidXML() uses an insecure SAX parser to validate the input string, which allows for XXE attacks in all scripts which use this method to validate user input, potentially allowing an attacker to read sensitive data on the filesystem, perform same-site-request-forgery (SSRF), port-scanning behind the firewall or DoS the application.
network
low complexity
apache CWE-611
critical
9.8