CVE-2013-6348

EPSS 2.8%

Apache Struts is vulnerable to Cross-site Scripting

Published: 5/17/2022Modified: 12/8/2024

Description

Multiple cross-site scripting (XSS) vulnerabilities in Apache Struts 2.3.15.3 allow remote attackers to inject arbitrary web script or HTML via the namespace parameter to (1) actionNames.action and (2) showConfig.action in `config-browser/`.

Affected packages (1)

References (8)