-
CVSS Score
-The vulnerability stems from improper input validation in Struts 1 plugin's handling of ActionMessage. Proof includes:
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| org.apache.struts:struts2-struts1-plugin | maven | <= 2.3.37 |