← Back to CVE List

CVE-2017-9802

Published: 2017-08-14T13:29Z
Last Modified: 2024-11-21T03:36Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
The Javascript method Sling.evalString() in Apache Sling Servlets Post before 2.3.22 uses the javascript 'eval' function to parse input strings, which allows for XSS attacks by passing specially crafted input strings. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt