CVE-2016-2162: XSS
Apache Struts 2.x before 2.3.25 does not sanitize text in the Locale object constructed by I18NInterceptor, which might allow remote attackers to conduct cross-site scripting (XSS) attacks via unspecified vectors involving language display.
Other sources
Apache Struts 2.x before 2.3.28 does not sanitize text in the Locale object constructed by I18NInterceptor, which might allow remote attackers to conduct cross-site scripting (XSS) attacks via unspecified vectors involving language display.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-2162?
CVE-2016-2162 has been rated as high risk due to the potential for cross-site scripting (XSS) attacks.
How do I fix CVE-2016-2162?
To mitigate CVE-2016-2162, upgrade your Apache Struts version to at least 2.3.28 or later.
What versions of Apache Struts are affected by CVE-2016-2162?
CVE-2016-2162 affects Apache Struts versions prior to 2.3.28.
What type of vulnerability is CVE-2016-2162?
CVE-2016-2162 is categorized as a cross-site scripting (XSS) vulnerability.
Is there a public disclosure for CVE-2016-2162?
Yes, CVE-2016-2162 is documented in various public advisories and vulnerability databases.