天下漏洞,尽知其名
MEDIUM

CVE-2026-91204 Apache Roller 存储型跨站脚本漏洞

影响匿名攻击者可存储恶意链接,诱导访客点击后执行脚本

AI 研判

Apache Roller 6.1.5 在启用评论 HTML 功能并使用 HTMLSubset 评论格式化器时,未对 javascript: URI 链接做充分过滤,导致存储型 XSS。匿名远程攻击者可提交含恶意链接的评论,该链接在 HTML 格式化后仍保留,访客点击即在浏览器中执行脚本。

影响范围

Apache Roller

Apache Roller 6.1.5;仅影响同时启用 users.comments.htmlenabled=true 且使用 HTMLSubset 评论格式化器的站点。

漏洞详情

漏洞类型为存储型跨站脚本(XSS),成因是网页生成时对输入中和不当。评论格式化器在还原链接时未限制 URI 协议,使 javascript: 链接得以保留。攻击者以匿名身份提交评论,待评论发布后,任何点击该链接的访客都会触发脚本执行。

利用条件与风险

利用前提是站点开启评论 HTML 并采用 HTMLSubset 格式化器;若启用评论审核,则需评论通过审核后才会生效。实战中可窃取会话、冒充用户操作,风险中等。

修复建议

官方建议升级至 Apache Roller 6.1.6 或更高版本,该版本将还原链接限制为 http、https 和 mailto。临时缓解可关闭评论 HTML 功能或启用评论审核。

原始情报

Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’) in Apache Roller 6.1.5 allows an anonymous remote attacker to store a comment containing a javascript: URI link that survives HTML comment formatting and can execute script in the browser of a visitor who clicks it. This affects only sites that enable HTML in comments (users.comments.htmlenabled=true) together with the HTMLSubset comment formatter; comment moderation, where enabled, delays publication. Users are recommended to upgrade to Apache Roller 6.1.6 or later, which restricts restored links to http, https and mailto URIs.