CVE-2009-1275: XSS
Apache Tiles 2.1 before 2.1.2, as used in Apache Struts and other products, evaluates Expression Language (EL) expressions twice in certain circumstances, which allows remote attackers to conduct cross-site scripting (XSS) attacks or obtain sensitive information via unspecified vectors, related to the (1) tiles:putAttribute and (2) tiles:insertTemplate JSP tags.
Other sources
Apache Tiles 2.1 before 2.1.2, as used in Apache Struts and other products, evaluates Expression Language (EL) expressions twice in certain circumstances, which allows remote attackers to conduct cross-site scripting (XSS) attacks or obtain sensitive information via unspecified vectors, related to the (1) tiles:putAttribute and (2) tiles:insertTemplate JSP tags.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2009-1275?
CVE-2009-1275 is considered a high severity vulnerability due to its potential for enabling cross-site scripting (XSS) attacks.
How do I fix CVE-2009-1275?
To fix CVE-2009-1275, upgrade to Apache Tiles version 2.1.2 or later.
What versions of Apache Tiles are affected by CVE-2009-1275?
CVE-2009-1275 affects Apache Tiles versions 2.1.0 and 2.1.1.
Can CVE-2009-1275 affect websites using Apache Struts?
Yes, CVE-2009-1275 can impact websites using Apache Struts if they also utilize affected versions of Apache Tiles.
What type of attack can be performed using CVE-2009-1275?
CVE-2009-1275 can be exploited to conduct cross-site scripting (XSS) attacks.