天下漏洞,尽知其名
MEDIUM

CVE-2026-82546 Apache Roller 跨站脚本漏洞

影响未授权攻击者可存储恶意链接,诱导访客点击后执行脚本

AI 研判

Apache Roller 6.1.5 的 Trackback 接收端点存在存储型跨站脚本漏洞。未认证远程攻击者可在允许评论和 Trackback 的已发布文章上提交特制的评论作者 URL,该值经默认审核流程被批准后渲染为活动链接,访客点击即在博客域内执行脚本。

影响范围

Apache Roller

Apache Roller 6.1.5;官方建议升级至 6.1.6 或更高版本。

漏洞详情

漏洞类型为 CWE-79 跨站脚本(存储型)。成因是 Web 页面生成时对输入未做正确中和,Trackback 端点接收的评论作者 URL 未限制为 HTTP(S) 协议,默认的验证与审核配置又会自动批准该值并渲染为可点击链接。攻击者借此注入 javascript: 等伪协议链接,访客点击后脚本在博客源下执行。

利用条件与风险

利用前提是目标博客存在已发布且接受评论与 Trackback 的文章,并使用默认的 Trackback 验证与审核设置;无需认证即可远程投递,但需诱导访客点击恶意链接,CVSS 6.1 属中危。

修复建议

官方修复方案为升级至 Apache Roller 6.1.6 或更高版本,该版本移除入站 Trackback 支持并抑制非 HTTP(S) 的评论作者链接。无法升级时应禁用 Trackback 功能并删除不可信的 Trackback 评论。

原始情报

Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’) in Apache Roller 6.1.5 allows an unauthenticated remote attacker to store a crafted comment-author URL through the incoming Trackback endpoint when a published entry accepts comments and Trackbacks. The shipped Trackback, verification and moderation defaults allow the value to be approved and rendered as an active link; a visitor who clicks the link executes script in the weblog’s origin. Users are recommended to upgrade to Apache Roller 6.1.6 or later, which removes incoming Trackback support and suppresses non-HTTP(S) comment-author links. Users unable to upgrade should disable Trackbacks and remove untrusted Trackback comments.