QID 995388
Date Published: 2023-09-25
QID 995388: Java (Maven) Security Update for org.apache.struts:struts-core (GHSA-9cjh-qmvx-436c)
Cross-site scripting (XSS) vulnerability in Apache Struts 1.2.7, and possibly other versions allows remote attackers to inject arbitrary web script or HTML via the query string, which is not properly quoted or filtered when the request handler generates an error message.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-9cjh-qmvx-436c for updates and patch information.
Vendor References
- GHSA-9cjh-qmvx-436c -
github.com/advisories/GHSA-9cjh-qmvx-436c
CVEs related to QID 995388
Software Advisories
| Advisory ID | Software | Component | Link |
|---|