Description
XSLTResult in Apache Struts 2.x before 2.3.20.2, 2.3.24.x before 2.3.24.2, and 2.3.28.x before 2.3.28.1 allows remote attackers to execute arbitrary code via the stylesheet location parameter.
Remediation
References
http://struts.apache.org/docs/s2-031.html
http://www.securityfocus.com/bid/88826
http://www.securitytracker.com/id/1035664
Related Vulnerabilities
CVE-2023-46131 Vulnerability in maven package org.grails:grails-databinding
CVE-2012-3451 Vulnerability in maven package org.apache.cxf:cxf-bundle-minimal
CVE-2023-31098 Vulnerability in maven package org.apache.inlong:manager-pojo
CVE-2022-3952 Vulnerability in maven package com.manydesigns:portofino-microservice-launcher
CVE-2023-0871 Vulnerability in maven package org.opennms.core:org.opennms.core.xml