CVE-2026-91206 Apache Roller 反射型跨站脚本漏洞
影响攻击者可对已加载认证表单的用户实施反射型XSS
Apache Roller 6.1.5 的 LdapCommentAuthenticator 组件在生成 HTML 表单时未对请求参数值进行转义,导致反射型跨站脚本漏洞。远程攻击者可构造恶意链接,诱导已加载该认证表单的用户点击,从而在其浏览器中执行任意脚本。该漏洞仅影响启用了 LdapCommentAuthenticator 的站点。
影响范围
Apache Roller 6.1.5,且站点需配置使用可选的 LdapCommentAuthenticator;官方建议升级至 6.1.6 或更高版本。
漏洞详情
漏洞类型为反射型跨站脚本(CWE-79)。成因是 LDAP 评论认证器在将请求参数值写入其 HTML 表单时未进行转义处理。攻击者可将恶意脚本作为参数值构造链接,当受害者访问该链接且其会话已加载认证器表单时,脚本会在受害者浏览器上下文中执行。
利用条件与风险
利用前提是目标站点启用了 LdapCommentAuthenticator,且受害者已加载该认证表单并点击攻击者构造的链接。属于需要用户交互的反射型 XSS,实战中可用于会话劫持或钓鱼,风险中等。
修复建议
官方修复方案为升级至 Apache Roller 6.1.6 或更高版本,该版本对反射值进行了转义。临时缓解措施为禁用 LdapCommentAuthenticator 或避免点击不可信链接,暂无其他公开信息。
Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’) in Apache Roller 6.1.5 allows a remote attacker to perform reflected cross-site scripting through the optional LDAP comment authenticator, which writes request parameter values into its HTML form without escaping. This affects only sites configured to use LdapCommentAuthenticator, and a victim whose session has already loaded the authenticator form must follow a crafted link. Users are recommended to upgrade to Apache Roller 6.1.6 or later, which escapes the reflected values.