Sceawere
Vulnerability Detail
CVE-2026-82387UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Apache Roller Stored XSS Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.4
- Creation Date
- 4h ago
- Vendor
- Apache Software Foundation
- Product
- Apache Roller
- Attack Type
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Apache Roller 6.1.5 allows a user with media-upload rights to store active content on Roller's origin, because the media upload feature trusts the upload-supplied content type and serves the stored file back with that type. A victim who opens the uploaded file executes the stored script. Media uploads are disabled by default; only installations that enable them are affected, and the shipped type restrictions do not block active content once uploads are on. Users are recommended to upgrade to Apache Roller 6.1.6 or later, which derives the stored type from file content and serves non-image media as a download.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.4",
"pubDate": "2026-09-28T08:16:42.647Z",
"pubdate": "2026-09-28T08:16:42.647Z",
"executiveSummary": "Apache Roller 6.1.5 is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability originating from insecure media file handling. This vulnerability is classified as CWE-79: Improper Neutralization of Input During Web Page Generation.\nThe flaw exists within the media upload feature, where the system relies exclusively on the user-provided Content-Type header when storing and serving uploaded files. This trust in client-supplied metadata allows authenticated users with media-upload privileges to upload malicious files containing active scripts.\nWhen a victim accesses the stored file, the browser interprets the script based on the attacker-controlled Content-Type, leading to code execution within the victim's session on the Apache Roller origin. While media uploads are disabled by default, environments that have enabled this feature are at significant risk. The exploitation allows attackers to perform unauthorized actions, hijack sessions, or exfiltrate sensitive data. Immediate remediation through upgrading to version 6.1.6 or later is required to enforce robust file type validation based on content inspection rather than user-provided headers.",
"technicalDetails": "The root cause of this vulnerability lies in an improper input validation mechanism within the Apache Roller 6.1.5 media management subsystem. The application fails to perform deep content inspection on uploaded binary objects, relying instead on the Content-Type header provided by the client during the POST request. By spoofing the Content-Type to match an executable format (e.g., text/html) while uploading a file containing malicious JavaScript payloads, an attacker can bypass existing extension-based restrictions.\nThe exploitation flow is as follows: First, an attacker with valid media-upload permissions navigates to the media management interface. Second, the attacker uploads a file, such as an HTML document containing arbitrary script tags, while manipulating the upload request headers to misrepresent the file type as a standard image or benign media type. Third, Apache Roller stores the file on the server's origin. Finally, when a target user or administrator views or downloads the file via the Roller origin, the server serves the malicious content using the attacker-supplied Content-Type header. Consequently, the victim's browser executes the embedded script in the context of the Apache Roller web application.\nThis vulnerability is strictly an authenticated attack vector, requiring the attacker to possess sufficient privileges to perform media uploads. Because the application explicitly trusts the upload-supplied MIME type, it bypasses the security logic that is intended to prevent the hosting of active web content. The payload behavior is limited only by the attacker's ability to craft JavaScript that interacts with the browser's Document Object Model (DOM) of the Roller site. Post-exploitation impact includes the potential for session hijacking through credential theft, the execution of unauthorized administrative operations, or the delivery of further malicious payloads to other authenticated users interacting with the platform.\nThe vulnerability affects Apache Roller 6.1.5. Installations that have not enabled media uploads remain unaffected by this specific vector. The remediation logic introduced in Apache Roller 6.1.6 shifts the security model from trust-on-input to a server-side validation model. Specifically, the updated version derives the content type directly from the file's binary signature (magic numbers) and forces a download disposition for non-image media types, thereby preventing browsers from executing stored scripts as web pages."
}