Cross-Site Scripting Vulnerability in Apache Struts by The Apache Software Foundation
CVE-2015-5169
6.1MEDIUM
Summary
A cross-site scripting (XSS) vulnerability exists in Apache Struts versions prior to 2.3.20. This flaw allows attackers to inject arbitrary web scripts into the application, potentially leading to the theft of sensitive information, session hijacking, or defacement of the website. Proper validation and sanitization of user inputs are essential to mitigate the risks associated with this vulnerability.
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved