CVE-2013-6348

EPSS 2.8%

Apache Struts is vulnerable to Cross-site Scripting

發布日:2022/5/17修改日:2024/12/8

描述

Multiple cross-site scripting (XSS) vulnerabilities in Apache Struts 2.3.15.3 allow remote attackers to inject arbitrary web script or HTML via the namespace parameter to (1) actionNames.action and (2) showConfig.action in `config-browser/`.

受影響套件(1)

參考連結(8)