peter bassill · operator
$ cve CVE-2011-1772 JSON

CVE-2011-1772 EXPLOIT

2.6
LOW · CVSS 2.0 · EPSS 33.3% (pctl 98)

Patch early

A public exploit exists.

Description

Multiple cross-site scripting (XSS) vulnerabilities in XWork in Apache Struts 2.x before 2.2.3, and OpenSymphony XWork in OpenSymphony WebWork, allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) an action name, (2) the action attribute of an s:submit element, or (3) the method attribute of an s:submit element.

Scoring

CVSS2.6 (LOW, v2.0)
VectorAV:N/AC:H/Au:N/C:N/I:P/A:N
EPSS33.35% — more likely to be exploited than 98% of all CVEs
WeaknessCWE-79
On CISA KEVno
Public exploityes
Published2011-05-13
Last modified2026-06-16

Affected (3)

VendorProduct
apachestruts
opensymphonywebwork
opensymphonyxwork

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD