{"id":"GHSA-9848-v244-962p","summary":"Withdrawn Advisory: Apache Struts XSS","details":"### Withdrawn Advisory\nThis advisory has been withdrawn because it was deemed invalid. This link is maintained to preserve external references.\n\n### Original Description\nMultiple cross-site scripting (XSS) vulnerabilities in Apache Struts 1.3.10 allow remote attackers to inject arbitrary web script or HTML via (1) the name parameter to struts-examples/upload/upload-submit.do, or the message parameter to (2) `struts-cookbook/processSimple.do` or (3) `struts-cookbook/processDyna.do`.","aliases":["CVE-2012-1007"],"modified":"2026-09-10T03:49:21.658324158Z","published":"2022-05-14T02:21:24Z","withdrawn":"2026-05-14T13:03:54Z","database_specific":{"nvd_published_at":"2012-02-07T04:09:00Z","cwe_ids":["CWE-79"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2022-11-03T21:09:51Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2012-1007"},{"type":"WEB","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/73052"}],"affected":[{"package":{"name":"org.apache.struts:struts-core","ecosystem":"Maven","purl":"pkg:maven/org.apache.struts/struts-core"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"1.3.10"}]}],"versions":["1.3.10","1.3.5","1.3.8","1.3.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-9848-v244-962p/GHSA-9848-v244-962p.json"}},{"package":{"name":"struts:struts","ecosystem":"Maven","purl":"pkg:maven/struts/struts"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"1.3.10"}]}],"versions":["1.0.2","1.1","1.1-b2-20021124","1.1-b3","1.1-beta-2","1.1-rc1","1.1-rc2","1.2.2","1.2.4","1.2.7","1.2.8","1.2.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-9848-v244-962p/GHSA-9848-v244-962p.json"}}],"schema_version":"1.9.0"}