Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-56f8-g68r-j699

Опубликовано: 17 мая 2022
Источник: github
Github: Прошло ревью

Описание

Cross-site Scripting in Apache Struts

Multiple Cross-Site Scripting (XSS) in XWork generated error pages in Apache Struts. By default, XWork doesn't escape action's names in automatically generated error page, allowing for a successful XSS attack. When Dynamic Method Invocation (DMI) is enabled, the action name is generated dynamically base on request parameters. This allows to call non-existing page and method to produce error page with injected code as below. As of Struts 2.2.3 the action names are escaped when automatically generated error pages are rendered.

Пакеты

Наименование

org.apache.struts:struts2-core

maven
Затронутые версииВерсия исправления

< 2.2.3

2.2.3

EPSS

Процентиль: 98%
0.53371
Средний

Дефекты

CWE-79

Связанные уязвимости

redhat
почти 15 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in XWork in Apache Struts 2.x before 2.2.3, and OpenSymphony XWork in OpenSymphony WebWork, allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) an action name, (2) the action attribute of an s:submit element, or (3) the method attribute of an s:submit element.

nvd
больше 14 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in XWork in Apache Struts 2.x before 2.2.3, and OpenSymphony XWork in OpenSymphony WebWork, allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) an action name, (2) the action attribute of an s:submit element, or (3) the method attribute of an s:submit element.

debian
больше 14 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in XWork in Apache ...

EPSS

Процентиль: 98%
0.53371
Средний

Дефекты

CWE-79