CVE-2026-86507 Apache Roller 存储型XSS漏洞
影响匿名攻击者可存储恶意脚本,管理员查看评论时触发执行
Apache Roller 6.1.5 在评论作者 URL 字段未正确中和输入,导致存储型跨站脚本漏洞。匿名远程攻击者可提交带有恶意脚本的评论作者 URL,当博客版主或全局管理员在评论管理页面查看该评论时,脚本会在其会话中执行。
影响范围
Apache Roller 6.1.5 受影响,官方建议升级至 6.1.6 或更高版本。
漏洞详情
漏洞类型为存储型 XSS(CWE-79),成因是评论作者 URL 输入未做充分的中和或转义处理。攻击者无需认证即可在允许评论的博客上提交恶意 URL,脚本被持久化存储。当管理员打开评论管理页面时,浏览器会解析并执行该脚本,从而在管理员会话上下文中运行。
利用条件与风险
利用前提是站点至少有一个博客允许评论,且版主会查看提交的评论,无需非默认服务器配置。实战中可劫持管理员会话、执行管理操作,风险中等。
修复建议
官方修复方案为升级至 Apache Roller 6.1.6 或更高版本;临时缓解措施暂无公开信息,可考虑限制评论功能或对评论作者 URL 进行过滤。
Improper neutralization of input in Apache Roller 6.1.5 allows an anonymous remote attacker to store a crafted comment-author URL that can execute script in the session of a weblog moderator or global administrator when the comment management page is viewed. This affects sites that permit comments on at least one weblog and whose moderator subsequently reviews the submitted comment; no non-default server setting is required. Users are recommended to upgrade to Apache Roller 6.1.6 or later.