{"id":"GHSA-2c6q-rgvj-66rx","summary":"Apache Tiles Vulnerable to XSS via EL Expression Injection","details":"Apache Tiles 2.1 before 2.1.2, as used in Apache Struts and other products, evaluates Expression Language (EL) expressions twice in certain circumstances, which allows remote attackers to conduct cross-site scripting (XSS) attacks or obtain sensitive information via unspecified vectors, related to the (1) `tiles:putAttribute` and (2) `tiles:insertTemplate` JSP tags.","aliases":["CVE-2009-1275"],"modified":"2024-12-06T05:37:15.914229Z","published":"2022-05-02T03:23:16Z","database_specific":{"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2024-01-23T18:19:44Z","nvd_published_at":"2009-04-09T15:08:00Z","cwe_ids":["CWE-87","CWE-917"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2009-1275"},{"type":"WEB","url":"http://svn.apache.org/viewvc/tiles/framework/trunk/src/site/apt/security/security-bulletin-1.apt?revision=741913"}],"affected":[{"package":{"name":"org.apache.tiles:tiles-core","ecosystem":"Maven","purl":"pkg:maven/org.apache.tiles/tiles-core"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.1"},{"fixed":"2.1.2"}]}],"versions":["2.1.0","2.1.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-2c6q-rgvj-66rx/GHSA-2c6q-rgvj-66rx.json"}}],"schema_version":"1.9.0"}