Sceawere

Vulnerability Detail

CVE-2026-91204UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Apache Roller Stored XSS Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.1
Creation Date
4h ago
Vendor
Apache Software Foundation
Product
Apache Roller
Attack Type
CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Apache Roller 6.1.5 allows an anonymous remote attacker to store a comment containing a javascript: URI link that survives HTML comment formatting and can execute script in the browser of a visitor who clicks it. This affects only sites that enable HTML in comments (users.comments.htmlenabled=true) together with the HTMLSubset comment formatter; comment moderation, where enabled, delays publication. Users are recommended to upgrade to Apache Roller 6.1.6 or later, which restricts restored links to http, https and mailto URIs.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.1",
  "pubDate": "2026-09-28T08:16:42.887Z",
  "pubdate": "2026-09-28T08:16:42.887Z",
  "executiveSummary": "A Stored Cross-Site Scripting (XSS) vulnerability exists in Apache Roller 6.1.5 due to improper neutralization of user-supplied input within the comment system.\nThe vulnerability occurs when HTML is enabled in comments (users.comments.htmlenabled=true) using the HTMLSubset formatter.\nAn anonymous remote attacker can inject a 'javascript:' URI within an HTML anchor tag, which remains unfiltered.\nWhen a visitor interacts with the malicious link, the embedded script executes within the context of the victim's browser session.\nThe risk is significant as it allows for unauthorized script execution, potentially leading to session hijacking, credential theft, or unauthorized actions performed on behalf of the user.\nExploitation is contingent upon specific configuration settings, but does not require authentication from the attacker, making this a remote attack vector against the web application.",
  "technicalDetails": "The root cause of this vulnerability is an insufficient sanitization mechanism within the Apache Roller HTMLSubset comment formatter. The application fails to adequately validate or restrict the URI schemes permitted within anchor tag 'href' attributes when HTML comment support is enabled.\nIn the vulnerable version 6.1.5, the filtering logic allows 'javascript:' pseudo-protocols to pass through the sanitization process if the user has enabled HTML in comments via the 'users.comments.htmlenabled' configuration property.\nThe attack flow proceeds as follows: First, an anonymous attacker crafts a malicious comment payload containing an anchor element, such as <a href='javascript:alert(document.cookie)'>Click here</a>. Second, the attacker submits this comment to an Apache Roller blog post. Because the HTMLSubset formatter is active, the system incorrectly treats the javascript URI as a legitimate link destination rather than stripping or blocking the dangerous protocol.\nThird, the comment is stored in the application's backend database. If comment moderation is disabled, the payload is immediately rendered to other visitors. Even if moderation is enabled, the payload remains stored and will execute once a moderator approves the comment for public display.\nFourth, when an unsuspecting victim views the blog post and interacts with the malicious link, the browser executes the URI-encoded JavaScript within the security context of the origin site. This allows the attacker to bypass the Same-Origin Policy (SOP) to access session tokens, manipulate DOM elements, or exfiltrate sensitive data cached in the browser.\nThe vulnerability resides in the link handling logic of the HTML processing module. Apache Roller 6.1.5 and earlier are affected. By failing to whitelist permitted protocols (e.g., http, https, mailto), the application implicitly trusts user input that contains active script content. Post-exploitation impact includes persistent script execution across all users who view the compromised comment thread, facilitating large-scale client-side attacks without requiring administrative privileges or local access to the server."
}
CVE-2026-91204: Apache Roller Stored XSS Vulnerability (MEDIUM Severity, CVSS: 6.1) | Sceawere