CVE-2011-2087: XSS
Multiple cross-site scripting (XSS) vulnerabilities in component handlers in the javatemplates (aka Java Templates) plugin in Apache Struts 2.x before 2.2.3 allow remote attackers to inject arbitrary web script or HTML via an arbitrary parameter value to a .action URI, related to improper handling of value attributes in (1) FileHandler.java, (2) HiddenHandler.java, (3) PasswordHandler.java, (4) RadioHandler.java, (5) ResetHandler.java, (6) SelectHandler.java, (7) SubmitHandler.java, and (8) TextFieldHandler.java.
Other sources
Multiple cross-site scripting (XSS) vulnerabilities in component handlers in the javatemplates (aka Java Templates) plugin in Apache Struts 2.x before 2.2.3 allow remote attackers to inject arbitrary web script or HTML via an arbitrary parameter value to a .action URI, related to improper handling of value attributes in 1. FileHandler.java 1. HiddenHandler.java 1. PasswordHandler.java 1. RadioHandler.java 1. ResetHandler.java 1. SelectHandler.java 1. SubmitHandler.java 1. TextFieldHandler.java
— GitHub
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-2087?
CVE-2011-2087 is categorized as a medium severity vulnerability due to its potential for cross-site scripting attacks.
How do I fix CVE-2011-2087?
To fix CVE-2011-2087, upgrade Apache Struts to version 2.2.3 or later.
Which versions of Apache Struts are affected by CVE-2011-2087?
CVE-2011-2087 affects Apache Struts versions from 2.0.0 to 2.2.2.
What type of attack is associated with CVE-2011-2087?
CVE-2011-2087 is associated with cross-site scripting (XSS) attacks that allow attackers to inject arbitrary web scripts or HTML.
Is there a patch available for CVE-2011-2087?
Yes, a patch is available by upgrading to Apache Struts version 2.2.3 or later.