CVE-2012-1006
Apache Struts Multiple Cross-site Scripting Vulnerabilities
EPSS 76.2%
Description
Multiple cross-site scripting (XSS) vulnerabilities in Apache Struts 2.0.14 and 2.2.3 allow remote attackers to inject arbitrary web script or HTML via the (1) name or (2) lastName parameter to `struts2-showcase/person/editPerson.action`, or the (3) clientName parameter to `struts2-rest-showcase/orders`.
How to fix CVE-2012-1006
To remediate CVE-2012-1006, upgrade the affected package to a fixed version below.
- Maven/org.apache.struts:struts2-parent—upgrade to 2.1.2 or later
Is CVE-2012-1006 being exploited?
Likely — EPSS is 76.2%, placing CVE-2012-1006 in the top tier of vulnerabilities by exploitation probability. Prioritise patching.
Affected packages (1)
- from 0, < 2.1.2