CVE-2011-1772: XSS
Multiple cross-site scripting (XSS) vulnerabilities in XWork in Apache Struts 2.x before 2.2.3, and OpenSymphony XWork in OpenSymphony WebWork, allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) an action name, (2) the action attribute of an s:submit element, or (3) the method attribute of an s:submit element.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2011-1772?
CVE-2011-1772 has a medium severity rating due to its cross-site scripting vulnerabilities.
How do I fix CVE-2011-1772?
To fix CVE-2011-1772, upgrade Apache Struts to version 2.2.3 or later.
Which versions of Apache Struts are affected by CVE-2011-1772?
CVE-2011-1772 affects Apache Struts versions prior to 2.2.3, including 2.0.x and 2.1.x.
What types of attacks can CVE-2011-1772 facilitate?
CVE-2011-1772 can facilitate cross-site scripting (XSS) attacks, allowing attackers to inject malicious scripts.
Is CVE-2011-1772 related to OpenSymphony XWork or WebWork?
Yes, CVE-2011-1772 also affects OpenSymphony XWork and WebWork, allowing similar XSS vulnerabilities.