[MAVEN:GHSA-9848-V244-962P] Apache Struts XSS

Severity Moderate
Affected Packages 3
CVEs 1

Multiple cross-site scripting (XSS) vulnerabilities in Apache Struts 1.3.10 allow remote attackers to inject arbitrary web script or HTML via (1) the name parameter to struts-examples/upload/upload-submit.do, or the message parameter to (2) struts-cookbook/processSimple.do or (3) struts-cookbook/processDyna.do.

ID
MAVEN:GHSA-9848-V244-962P
Severity
moderate
URL
https://github.com/advisories/GHSA-9848-v244-962p
Published
2022-05-14T02:21:24
(2 years ago)
Modified
2023-08-14T23:23:20
(13 months ago)
Rights
Maven Security Team
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/struts/struts struts struts <= 1.3.10
Affected pkg:maven/org.apache.struts/struts2-parent org.apache.struts struts2-parent <= 1.3.10
Affected pkg:maven/org.apache.struts/struts-core org.apache.struts struts-core <= 1.3.10
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...