Cross-site scripting in Apache Struts
Low severity
GitHub Reviewed
Published
May 1, 2022
to the GitHub Advisory Database
•
Updated Jan 27, 2023
Description
Published by the National Vulnerability Database
Mar 30, 2006
Published to the GitHub Advisory Database
May 1, 2022
Reviewed
Jun 7, 2022
Last updated
Jan 27, 2023
Cross-site scripting (XSS) vulnerability in (1) LookupDispatchAction and possibly (2) DispatchAction and (3) ActionDispatcher in Apache Software Foundation (ASF) Struts before 1.2.9 allows remote attackers to inject arbitrary web script or HTML via the parameter name, which is not filtered in the resulting error message.
References