CVE-2026-82381 Apache Roller 存储型跨站脚本漏洞
影响具有作者权限的用户可存储脚本,在其他作者或管理员浏览器中执行
Apache Roller 6.1.5 存在存储型跨站脚本漏洞。拥有博客作者权限的用户可提交特制内容,该内容在写入作者界面时未正确编码,被直接拼入 JavaScript 字符串字面量和标记输出点,从而在其他作者或管理员浏览时执行。
影响范围
Apache Roller 6.1.5;官方建议升级至 6.1.6 或更高版本。
漏洞详情
漏洞类型为存储型跨站脚本(CWE-79)。成因是网页生成时对用户输入中和不当,作者提交的内容被直接写入作者界面的 JavaScript 字符串字面量与 HTML 标记输出点,缺少必要编码。攻击者以作者身份保存恶意内容后,其他作者或管理员打开相关页面即触发脚本执行。
利用条件与风险
利用需攻击者拥有博客作者权限,且目标博客存在多个互不信任的作者或管理员;无需开启可选功能或非默认配置,实战中可窃取会话或冒充管理员操作。
修复建议
升级至 Apache Roller 6.1.6 或更高版本,该版本将相关值移出 JavaScript 字面量并以文本形式输出;暂无其他公开临时缓解措施信息。
Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’) in Apache Roller 6.1.5 allows a user with authoring rights on a weblog to store crafted content that is later written into the authoring UI’s JavaScript string literals and markup sinks without proper encoding, causing the stored script to execute in another author’s or administrator’s browser. No optional feature or non-default configuration is required; this affects weblogs with multiple authors or administrators who are not mutually trusted. Users are recommended to upgrade to Apache Roller 6.1.6 or later, which moves those values out of JavaScript literals and writes them as text.