Severity: Moderate
CVSS 3.1: 6.1 (medium) CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Affected versions:
- Apache Roller 6.1.5
Description:
Improper Neutralization of Input During Web Page Generation ('Cross-site
Scripting') in Apache Roller 6.1.5 allows an anonymous remote attacker to store
a comment containing a javascript: URI link that survives HTML comment
formatting and can execute script in the browser of a visitor who clicks it.
This affects only sites that enable HTML in comments
(users.comments.htmlenabled=true) together with the HTMLSubset comment
formatter; comment moderation, where enabled, delays publication. Users are
recommended to upgrade to Apache Roller 6.1.6 or later, which restricts
restored links to http, https and mailto URIs.
Credit:
姬珏 (CyberLeo) (finder)
References:
https://github.com/apache/roller/pull/190
https://roller.apache.org/
https://www.cve.org/CVERecord?id=CVE-2026-91204