CVE-2015-2992: XSS
Apache Struts before 2.3.20 has a cross-site scripting (XSS) vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is Apache Struts before 2.3.20 cross-site scripting (XSS) vulnerability?
Apache Struts before 2.3.20 is vulnerable to cross-site scripting (XSS), which allows attackers to inject malicious scripts into web pages viewed by users.
What is the severity of CVE-2015-2992?
The severity of CVE-2015-2992 is medium with a CVSS score of 6.1.
How does the XSS vulnerability in Apache Struts before 2.3.20 affect software?
The XSS vulnerability in Apache Struts before 2.3.20 can affect software that uses the vulnerable version, potentially allowing attackers to execute malicious scripts on the affected system.
How can I fix the Apache Struts before 2.3.20 XSS vulnerability?
To fix the XSS vulnerability in Apache Struts before 2.3.20, upgrade to a version that is not affected by the vulnerability (2.3.20 or later) or apply the available security patch.
Where can I find more information about CVE-2015-2992?
You can find more information about CVE-2015-2992 in the following resources: [JVN](http://jvn.jp/en/jp/JVN88408929/index.html), [JVNDB](http://jvndb.jvn.jp/en/contents/2015/JVNDB-2015-000124.html), [SecurityFocus](http://www.securityfocus.com/bid/76624).