CVE-2011-1772
Apache Struts 2.x <2.2.3 - XSS
Title source: llmDescription
Multiple cross-site scripting (XSS) vulnerabilities in XWork in Apache Struts 2.x before 2.2.3, and OpenSymphony XWork in OpenSymphony WebWork, allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) an action name, (2) the action attribute of an s:submit element, or (3) the method attribute of an s:submit element.
Exploits (1)
exploitdb
WRITEUP
VERIFIED
by Dr. Marian Ventuneac · textremotemultiple
https://www.exploit-db.com/exploits/35735
References (10)
Scores
EPSS
0.5923
EPSS Percentile
98.2%
Classification
CWE
CWE-79
Status
published
Affected Products (32)
apache/struts
apache/struts
apache/struts
apache/struts
apache/struts
apache/struts
apache/struts
apache/struts
apache/struts
apache/struts
apache/struts
apache/struts
apache/struts
apache/struts
apache/struts
... and 17 more
Timeline
Published
May 13, 2011
Tracked Since
Feb 18, 2026