天下漏洞,尽知其名
MEDIUM

CVE-2026-91206 Apache Roller 反射型跨站脚本漏洞

影响攻击者可对已加载认证表单的用户实施反射型XSS

AI 研判

Apache Roller 6.1.5 的 LdapCommentAuthenticator 组件在生成 HTML 表单时未对请求参数值进行转义,导致反射型跨站脚本漏洞。远程攻击者可构造恶意链接,诱导已加载该认证表单的用户点击,从而在其浏览器中执行任意脚本。该漏洞仅影响启用了 LdapCommentAuthenticator 的站点。

影响范围

Apache Roller

Apache Roller 6.1.5,且站点需配置使用可选的 LdapCommentAuthenticator;官方建议升级至 6.1.6 或更高版本。

漏洞详情

漏洞类型为反射型跨站脚本(CWE-79)。成因是 LDAP 评论认证器在将请求参数值写入其 HTML 表单时未进行转义处理。攻击者可将恶意脚本作为参数值构造链接,当受害者访问该链接且其会话已加载认证器表单时,脚本会在受害者浏览器上下文中执行。

利用条件与风险

利用前提是目标站点启用了 LdapCommentAuthenticator,且受害者已加载该认证表单并点击攻击者构造的链接。属于需要用户交互的反射型 XSS,实战中可用于会话劫持或钓鱼,风险中等。

修复建议

官方修复方案为升级至 Apache Roller 6.1.6 或更高版本,该版本对反射值进行了转义。临时缓解措施为禁用 LdapCommentAuthenticator 或避免点击不可信链接,暂无其他公开信息。

原始情报

Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’) in Apache Roller 6.1.5 allows a remote attacker to perform reflected cross-site scripting through the optional LDAP comment authenticator, which writes request parameter values into its HTML form without escaping. This affects only sites configured to use LdapCommentAuthenticator, and a victim whose session has already loaded the authenticator form must follow a crafted link. Users are recommended to upgrade to Apache Roller 6.1.6 or later, which escapes the reflected values.