An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability in Sling App CMS version 1.1.0 and prior may allow an authenticated remote attacker to perform a reflected cross site scripting (XSS) attack in the taxonomy management feature.
2022-11-02T13:15:19.997
2025-05-02T21:15:22.990
Modified
CVSSv3.1: 5.4 (MEDIUM)