Apache Struts <s:textfield> Cross-Site Scripting Vulnerability Fixed by 2.3.28
Description
(#A vulnerability has been identified in Apache Struts.#A remote attacker can exploit it in order to execute arbitrary Javascript or HTML code by inciting their victim into following a specially formed link.##The vulnerability is located in the "myinput" parameter when used with the "<s:textfield>" tag.##A proof of concept is available.)