Bugzilla – Bug 975281
VUL-0: CVE-2016-2162: struts: Apache Struts 2.x before 2.3.25 does not sanitize text in the Locale object constructed by I18NInterceptor
Last modified: 2016-04-22 08:37:29 UTC
CVE-2016-2162 Apache Struts 2.x before 2.3.25 does not sanitize text in the Locale object constructed by I18NInterceptor, which might allow remote attackers to conduct cross-site scripting (XSS) attacks via unspecified vectors involving language display. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2016-2162 http://www.securitytracker.com/id/1035272 http://struts.apache.org/docs/s2-030.html
bugbot adjusting priority
vulnerable code is not present