CVE-2011-2087

Apache Struts 2.x <2.2.3 - XSS

Title source: llm

Description

Multiple cross-site scripting (XSS) vulnerabilities in component handlers in the javatemplates (aka Java Templates) plugin in Apache Struts 2.x before 2.2.3 allow remote attackers to inject arbitrary web script or HTML via an arbitrary parameter value to a .action URI, related to improper handling of value attributes in (1) FileHandler.java, (2) HiddenHandler.java, (3) PasswordHandler.java, (4) RadioHandler.java, (5) ResetHandler.java, (6) SelectHandler.java, (7) SubmitHandler.java, and (8) TextFieldHandler.java.

Scores

EPSS 0.0139
EPSS Percentile 80.2%

Classification

CWE
CWE-79
Status published

Affected Products (30)

apache/struts
apache/struts
apache/struts
apache/struts
apache/struts
apache/struts
apache/struts
apache/struts
apache/struts
apache/struts
apache/struts
apache/struts
apache/struts
apache/struts
apache/struts
... and 15 more

Timeline

Published May 13, 2011
Tracked Since Feb 18, 2026