Anonymous users can create new JCR nodes via the AEM POST Servlet, which may allow attackers to inject malicious content, achieve persistent XSS, or abuse servlets registered by resource types for further attacks.
Log in to view the POC file snapshot cached by Shenlong Bot
Log in to view