peter bassill · operator
$ cve CVE-2016-6798 JSON

CVE-2016-6798

9.8
CRITICAL · CVSS 3.0 · EPSS 3.7% (pctl 89)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

In the XSS Protection API module before 1.0.12 in Apache Sling, the method XSS.getValidXML() uses an insecure SAX parser to validate the input string, which allows for XXE attacks in all scripts which use this method to validate user input, potentially allowing an attacker to read sensitive data on the filesystem, perform same-site-request-forgery (SSRF), port-scanning behind the firewall or DoS the application.

Scoring

CVSS9.8 (CRITICAL, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS3.67% — more likely to be exploited than 89% of all CVEs
WeaknessCWE-611
On CISA KEVno
Public exploitnone known
Published2017-07-19
Last modified2026-06-17

Affected (1)

VendorProduct
apachesling

References

→ the Explorer  ·  watch your stack  ·  NVD