Lucene search

K
osvGoogleOSV:GHSA-P3VW-FVWX-QCV5
HistoryMay 01, 2022 - 6:50 a.m.

Cross-site scripting in Apache Struts

2022-05-0106:50:42
Google
osv.dev
32
cross-site scripting
apache struts
xss
vulnerability
remote attackers
web script
html
parameter filtering

EPSS

0.015

Percentile

86.8%

Cross-site scripting (XSS) vulnerability in (1) LookupDispatchAction and possibly (2) DispatchAction and (3) ActionDispatcher in Apache Software Foundation (ASF) Struts before 1.2.9 allows remote attackers to inject arbitrary web script or HTML via the parameter name, which is not filtered in the resulting error message.

EPSS

0.015

Percentile

86.8%