Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:7780
HistoryNov 14, 2018 - 12:27 a.m.

Cross-Site Scripting (XSS)

2018-11-1400:27:47
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
8

0.002 Low

EPSS

Percentile

58.8%

Apache Struts is vulnerable to cross-site scripting. Lack of input validation and sanitization on the query string allows a remote attacker to inject arbitrary Javascript into a victim’s browser when the reuest handler generates an error message.

CPENameOperatorVersion
strutsle1.1
strutsle1.2.7

0.002 Low

EPSS

Percentile

58.8%