First published: Sat Nov 02 2013(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in Apache Struts 2.3.15.3 allow remote attackers to inject arbitrary web script or HTML via the namespace parameter to (1) actionNames.action and (2) showConfig.action in config-browser/.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache Struts | =2.3.15.3 | |
debian/libstruts1.2-java |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-6348 is classified as a high severity vulnerability due to the potential for remote code execution through cross-site scripting attacks.
To fix CVE-2013-6348, upgrade to Apache Struts version 2.3.16 or later where the vulnerability has been addressed.
Exploiting CVE-2013-6348 can allow attackers to execute arbitrary scripts in the context of a user's browser, impacting user data integrity and confidentiality.
CVE-2013-6348 affects Apache Struts version 2.3.15.3 specifically.
CVE-2013-6348 is primarily a server-side vulnerability that facilitates client-side exploitation through injected scripts.