Description
Cross-site scripting (XSS) vulnerability in Apache Struts before 2.3.20.
Remediation
References
http://jvn.jp/en/jp/JVN95989300/index.html
http://jvndb.jvn.jp/en/contents/2015/JVNDB-2015-000125.html
http://www.securityfocus.com/bid/76625
https://bugzilla.redhat.com/show_bug.cgi?id=1260087
https://security.netapp.com/advisory/ntap-20180629-0003/
https://struts.apache.org/docs/s2-025.html
Related Vulnerabilities
CVE-2021-32850 Vulnerability in npm package @claviska/jquery-minicolors
CVE-2018-19360 Vulnerability in maven package com.fasterxml.jackson.core:jackson-databind
CVE-2017-4960 Vulnerability in maven package org.cloudfoundry.identity:cloudfoundry-identity-server
CVE-2020-25711 Vulnerability in maven package org.infinispan:infinispan-server-rest
CVE-2020-7740 Vulnerability in npm package node-pdf-generator