VULNERABILITY INTELLIGENCE
CVE-2016-2162
CVSS score6.1 MEDIUM
EPSS probability7.78%
CISA KEVNot currently listed
Published2016-04-12
Last modified2026-06-17
Description
Apache Struts 2.x before 2.3.25 does not sanitize text in the Locale object constructed by I18NInterceptor, which might allow remote attackers to conduct cross-site scripting (XSS) attacks via unspecified vectors involving language display.