CVE-2005-3745
Apache Struts Cross-site scripting Vulnerability
EPSS 59.1%
Description
Cross-site scripting (XSS) vulnerability in Apache Struts 1.2.7, and possibly other versions allows remote attackers to inject arbitrary web script or HTML via the query string, which is not properly quoted or filtered when the request handler generates an error message.
How to fix CVE-2005-3745
No fixed version has been published yet. Mitigate by removing the affected package or applying upstream guidance from the references below.
- Maven/org.apache.struts:struts-core—no fix listed
Is CVE-2005-3745 being exploited?
Likely — EPSS is 59.1%, placing CVE-2005-3745 in the top tier of vulnerabilities by exploitation probability. Prioritise patching.
Affected packages (1)
- from 0, <= 1.2.7