GHSA-2j4q-9fff-236j, CVE-2016-2162
maven/org.apache.struts/struts2-core
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Apache Struts 2.x before 2.3.25 does not sanitize text in the Locale object constructed by I18NInterceptor, which might allow remote attackers to conduct cross-site scripting (XSS) attacks via unspecified vectors involving language display.
All versions starting from 2.0.0 before 2.3.28
Upgrade to version 2.3.28 or above.
2023-11-08
source |