CVE Feed

    Dashboard / CVE / CVE-2022-45064

    CVE-2022-45064

    The SlingRequestDispatcher doesn't correctly implement the RequestDispatcher API resulting in a generic type of include-based cross-site scripting issues on the Apache Sling level. The vulnerability is exploitable by an attacker that is able to include a resource with specific content-type and control the include path (i.e. writing content). The impact of a successful attack is privilege escalation to administrative power. Please update to Apache Sling Engine >= 2.14.0 and enable the "Check Content-Type overrides" configuration option.

    Published:Apr 13, 2023
    Last Modified:Jun 13, 2025
    EPS:Apr 13, 2023
    EPSS Score:0.00768
    CVSS Score:8

    Affected Products

    Vendor
    Apache
    Product
    Apache Sling Engine
    Vendor
    Apache
    Product
    Sling

    Exploits

    No exploit reference

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High