Apache Solr Search Template Cross Site Scripting Vulnerability
BID:67530
Info
Apache Solr Search Template Cross Site Scripting Vulnerability
| Bugtraq ID: | 67530 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 20 2014 12:00AM |
| Updated: | May 20 2014 12:00AM |
| Credit: | jkmac |
| Vulnerable: |
OpenCMS OpenCMS 9 Apache Solr 4.6 Apache Solr 4.5.1 Apache Solr 4.4 Apache Solr 4.3.1 Apache Solr 4.0 beta Apache Solr 4.0 alpha Apache Solr 3.6.1 Apache Solr 5.0 Apache Solr 4.5.0 Apache Solr 4.4 Apache Solr 4.3.0 Apache Solr 4.3 Apache Solr 4.2.1 Apache Solr 4.2.0 Apache Solr 4.1.0 Apache Solr 4.1 Apache Solr 4.0.0 Apache Solr 4.0-BETA Apache Solr 3.6.2 Apache Solr 3.6.0 |
| Not Vulnerable: | |
Discussion
Apache Solr Search Template Cross Site Scripting Vulnerability
The Apache Solr is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
The Apache Solr is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
Exploit / POC
Apache Solr Search Template Cross Site Scripting Vulnerability
An attacker can exploit this issue by enticing an unsuspecting user to follow a malicious URI.
An attacker can exploit this issue by enticing an unsuspecting user to follow a malicious URI.
References
Apache Solr Search Template Cross Site Scripting Vulnerability
References:
References:
- Apache Solr Homepage (Apache)
- XSS - find.searchhub.org, opencms version9 and others (seclists.org)