CVE-2026-82382 Apache Roller 跨站脚本漏洞
影响攻击者可对博客访客实施反射型XSS,窃取会话或钓鱼
Apache Roller 6.1.5 的捆绑 frontpage 主题在生成目录页面时,未对 blog-directory 参数进行正确转义,导致反射型跨站脚本漏洞。远程攻击者可构造恶意链接,诱导访客点击后在受害者浏览器中执行脚本。该问题仅影响使用捆绑 frontpage 主题的博客。
影响范围
Apache Roller 6.1.5;仅使用捆绑 frontpage 主题的博客受影响。官方建议升级至 6.1.6 或更高版本。
漏洞详情
漏洞类型为 CWE-79 反射型跨站脚本。目录页面在渲染时直接回显用户可控的 blog-directory 参数,未做上下文转义,攻击者可将脚本注入链接。受害者访问该构造链接后,脚本在其浏览器上下文中执行。
利用条件与风险
利用前提是目标博客使用捆绑 frontpage 主题,且受害者主动点击攻击者构造的链接;属于需要用户交互的反射型 XSS,实战中常用于会话劫持或钓鱼,风险中等。
修复建议
官方已在 Apache Roller 6.1.6 中对该反射参数进行校验和上下文转义,建议尽快升级。临时缓解可考虑停用或替换 frontpage 主题,并对相关参数输入进行过滤。
Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’) in Apache Roller 6.1.5 allows a remote attacker to perform reflected cross-site scripting against a visitor to a weblog using the bundled frontpage theme, by supplying a crafted blog-directory parameter that the directory page reflects without proper escaping. This affects only weblogs that use the bundled frontpage theme, and a victim must follow a crafted link for the script to execute. Users are recommended to upgrade to Apache Roller 6.1.6 or later, which validates and contextually escapes the reflected parameter.