CVE-2016-6798 describes a critical XML External Entity (XXE) vulnerability in the Apache Sling XSS Protection API module, specifically in versions prior to 1.0.12. The vulnerability arises from the insecure SAX parser used by the XSS.getValidXML() method, which fails to properly validate user input. This allows unauthenticated attackers to remotely exploit the system with low complexity, potentially leading to sensitive data disclosure, server-side request forgery (SSRF), port scanning, or denial of service (DoS). There is no evidence of active exploitation, publicly available exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.0.10CPE matchmatch criteria | cpe:2.3:a:apache:sling:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.