← Back

CVE-2013-4390

nvd nist
Published: Oct 24, 2013Modified: Apr 29, 2026

JSON object

Loading...
5.8
Vector
AV:N/AC:M/Au:N/C:P/I:P/A:N
Exploitability: 8.6 / Impact: 4.9
Source: NVD

Description

Open redirect vulnerability in the AbstractAuthenticationFormServlet in the Auth Core (org.apache.sling.auth.core) bundle before 1.1.4 in Apache Sling allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the resource parameter, related to "a custom login form and XSS."

Affected (6)

2 products
Sling
Sling Auth Core Component
Configuration A
6 vulnerable
Vulnerable SoftwareAffected Versions
All versions
Apache
Up to 1.1.2
Version 1.0.2
Version 1.0.4
Version 1.0.6
Version 1.1.0

References (8)

Timeline

No history available yet.