天下漏洞,尽知其名
MEDIUM

CVE-2026-82382 Apache Roller 跨站脚本漏洞

影响攻击者可对博客访客实施反射型XSS,窃取会话或钓鱼

AI 研判

Apache Roller 6.1.5 的捆绑 frontpage 主题在生成目录页面时,未对 blog-directory 参数进行正确转义,导致反射型跨站脚本漏洞。远程攻击者可构造恶意链接,诱导访客点击后在受害者浏览器中执行脚本。该问题仅影响使用捆绑 frontpage 主题的博客。

影响范围

Apache Roller

Apache Roller 6.1.5;仅使用捆绑 frontpage 主题的博客受影响。官方建议升级至 6.1.6 或更高版本。

漏洞详情

漏洞类型为 CWE-79 反射型跨站脚本。目录页面在渲染时直接回显用户可控的 blog-directory 参数,未做上下文转义,攻击者可将脚本注入链接。受害者访问该构造链接后,脚本在其浏览器上下文中执行。

利用条件与风险

利用前提是目标博客使用捆绑 frontpage 主题,且受害者主动点击攻击者构造的链接;属于需要用户交互的反射型 XSS,实战中常用于会话劫持或钓鱼,风险中等。

修复建议

官方已在 Apache Roller 6.1.6 中对该反射参数进行校验和上下文转义,建议尽快升级。临时缓解可考虑停用或替换 frontpage 主题,并对相关参数输入进行过滤。

原始情报

Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’) in Apache Roller 6.1.5 allows a remote attacker to perform reflected cross-site scripting against a visitor to a weblog using the bundled frontpage theme, by supplying a crafted blog-directory parameter that the directory page reflects without proper escaping. This affects only weblogs that use the bundled frontpage theme, and a victim must follow a crafted link for the script to execute. Users are recommended to upgrade to Apache Roller 6.1.6 or later, which validates and contextually escapes the reflected parameter.