vendor:
Struts
by:
Unknown
5.5
CVSS
MEDIUM
Cross-Site Scripting (XSS)
79
CWE
Product Name: Struts
Affected Version From: Unknown
Affected Version To: Unknown
Patch Exists: NO
Related CWE: Unknown
CPE: a:apache:struts
Platforms Tested:
Unknown
Cross-Site Scripting Vulnerability in Struts
The Struts application fails to properly sanitize user-supplied input, leading to a cross-site scripting vulnerability. An attacker can exploit this vulnerability to execute arbitrary script code in the browser of a user visiting the affected site. This can be used to steal authentication credentials and carry out further attacks.
Mitigation:
To mitigate this vulnerability, it is recommended to properly sanitize and validate all user-supplied input to prevent the execution of malicious scripts. Additionally, implementing content security policies and input validation can help prevent XSS attacks.