CVE-2013-2248

medium Apache
CVSS v3 Base Score
5.8
AV:N/AC:M/Au:N/C:P/I:P/A:N
EPSS Score
92.0%
Exploitation probability in 30 days
Top 0% most likely to be exploited
Attack Characteristics
Attack Vector
Network
Attack Complexity
M
Confidentiality
P
Integrity
P
Availability
None
Published: July 20, 2013 (4682 days ago)
Last Modified: April 29, 2026
Vendor: Apache
Source: NVD

Description

Multiple open redirect vulnerabilities in Apache Struts 2.0.0 through 2.3.15 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in a parameter using the (1) redirect: or (2) redirectAction: prefix.

CWE

CWE-20

Affected Products

apache struts

References