GHSA-rm26-w253-9qv7
Dashboard / Vulnerabilities / GHSA-rm26-w253-9qv7
Summary: Apache Struts Dojo Plugin XSS Vulnerability
Details: Multiple cross-site scripting (XSS) vulnerabilities in Dojo 0.4.1 and 0.4.2, as used in Apache Struts and other products, allow remote attackers to inject arbitrary web script or HTML via unspecified vectors involving (1) `xip_client.html` and (2) `xip_server.html` in `src/io/`.
References: https://nvd.nist.gov/vuln/detail/CVE-2007-6726, https://exchange.xforce.ibmcloud.com/vulnerabilities/49884, https://github.com/apache/struts-archive/blob/master/plugins/struts2-dojo-plugin, https://issues.apache.org/struts/browse/WW-2134, http://www.dojotoolkit.org/0-4-3-and-updated-0-4-1-0-4-2-builds, http://www.dojotoolkit.org/2007/05/26/0-4-3-released-0-4-2-and-0-4-1-users-should-upgrade-immediately, http://www.dojotoolkit.org/releaseNotes/0.4.3, http://www.securityfocus.com/bid/34660
Affected packages
Package
Name: org.apache.struts:struts2-dojo-plugin
Purl: pkg:maven/org.apache.struts/struts2-dojo-plugin
Affected ranges
Type: ECOSYSTEM
Events:
