CVE-2011-2087
Apache Struts 2.x <2.2.3 - XSS
Title source: llmDescription
Multiple cross-site scripting (XSS) vulnerabilities in component handlers in the javatemplates (aka Java Templates) plugin in Apache Struts 2.x before 2.2.3 allow remote attackers to inject arbitrary web script or HTML via an arbitrary parameter value to a .action URI, related to improper handling of value attributes in (1) FileHandler.java, (2) HiddenHandler.java, (3) PasswordHandler.java, (4) RadioHandler.java, (5) ResetHandler.java, (6) SelectHandler.java, (7) SubmitHandler.java, and (8) TextFieldHandler.java.
Scores
EPSS
0.0139
EPSS Percentile
80.2%
Classification
CWE
CWE-79
Status
published
Affected Products (30)
apache/struts
apache/struts
apache/struts
apache/struts
apache/struts
apache/struts
apache/struts
apache/struts
apache/struts
apache/struts
apache/struts
apache/struts
apache/struts
apache/struts
apache/struts
... and 15 more
Timeline
Published
May 13, 2011
Tracked Since
Feb 18, 2026