Cross-site scripting in Apache Struts - CVE-2016-1182

 

Cross-site scripting in Apache Struts - CVE-2016-1182

Published: November 30, -0001 / Updated: December 29, 2025


Vulnerability identifier: #VU2803
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
CVE-ID: CVE-2016-1182
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The disclosed vulnerability allows a remote attacker to perform cross-site scripting (XSS) attacks.

The vulnerability exists due to insufficient sanitization of user-supplied data. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's browser in context of vulnerable website.

Successful exploitation of this vulnerability may allow a remote attacker to steal potentially sensitive information, change appearance of the web page, perform phishing and drive-by-download attacks.


Affected software

Apache Struts
IBM Tivoli System Automation Application Manager
Jira Software Data Center
Jira Service Management Server
Jira Service Management Data Center
Jira Software Server
Integration Designer
eDiscovery Manager
Fedora
struts

How to mitigate CVE-2016-1182

Update to version 1.3.10.

Apache Struts - update to 1.3.10
Jira Software Server - update to 11.2.1
Jira Software Data Center - update to 11.2.1
Jira Service Management Server - update to 11.2.1
Jira Service Management Data Center - update to 11.2.1
struts - addressed in versions 1.3.10-18.fc23, 1.3.10-18.fc24
eDiscovery Manager - update to 2.2.2.3.8

External References

Related Security Bulletins