Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2016-4430

Apache Struts 2 2.3.20 through 2.3.28.1 mishandles token validation, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks via unspecified vectors.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.015
EPSS Ranking 80.5%
CVSS Severity
CVSS v3 Score 8.8
CVSS v2 Score 6.8
References
Products affected by CVE-2016-4430
  • Apache » Struts » Version: 2.3.20
    cpe:2.3:a:apache:struts:2.3.20
  • Apache » Struts » Version: 2.3.20.1
    cpe:2.3:a:apache:struts:2.3.20.1
  • Apache » Struts » Version: 2.3.20.3
    cpe:2.3:a:apache:struts:2.3.20.3
  • Apache » Struts » Version: 2.3.24
    cpe:2.3:a:apache:struts:2.3.24
  • Apache » Struts » Version: 2.3.24.1
    cpe:2.3:a:apache:struts:2.3.24.1
  • Apache » Struts » Version: 2.3.24.3
    cpe:2.3:a:apache:struts:2.3.24.3
  • Apache » Struts » Version: 2.3.28
    cpe:2.3:a:apache:struts:2.3.28
  • Apache » Struts » Version: 2.3.28.1
    cpe:2.3:a:apache:struts:2.3.28.1


Contact Us

Shodan ® - All rights reserved