天下漏洞,尽知其名
MEDIUM

CVE-2026-82387 Apache Roller 存储型XSS漏洞

影响具有上传权限的用户可存储脚本,受害者打开后执行

AI 研判

Apache Roller 6.1.5 的媒体上传功能信任上传文件自带的 Content-Type,并将其原样回传给访问者,导致存储型 XSS。攻击者需具备媒体上传权限,受害者打开上传文件即触发脚本执行。该功能默认关闭,仅启用媒体上传的实例受影响。

影响范围

Apache Roller

Apache Roller 6.1.5;官方建议升级至 6.1.6 或更高版本。其他版本是否受影响暂无公开信息。

漏洞详情

漏洞属于存储型跨站脚本(XSS),成因是 Web 页面生成时未对输入进行正确中和。媒体上传功能未校验文件真实类型,直接采用上传时声明的 Content-Type 存储并回传,使 HTML/JS 等主动内容可在 Roller 源下被浏览器执行。

利用条件与风险

利用前提是目标实例启用了媒体上传功能且攻击者拥有上传权限;默认配置下不受影响。一旦满足条件,可窃取会话或冒充受害者操作,实战风险中等。

修复建议

升级至 Apache Roller 6.1.6 或更高版本,该版本根据文件内容判定存储类型并将非图片媒体作为下载返回。临时缓解措施:关闭媒体上传功能,或限制上传权限与文件类型。暂无其他公开信息。

原始情报

Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’) in Apache Roller 6.1.5 allows a user with media-upload rights to store active content on Roller’s origin, because the media upload feature trusts the upload-supplied content type and serves the stored file back with that type. A victim who opens the uploaded file executes the stored script. Media uploads are disabled by default; only installations that enable them are affected, and the shipped type restrictions do not block active content once uploads are on. Users are recommended to upgrade to Apache Roller 6.1.6 or later, which derives the stored type from file content and serves non-image media as a download.