← All CVEs

CVE-2013-2248

medium · 5.8

A public exploit / detection template exists

Weaponised detection is publicly available, which meaningfully raises real-world risk regardless of CVSS. nuclei-templates

Multiple open redirect vulnerabilities in Apache Struts 2.0.0 through 2.3.15 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in a parameter using the (1) redirect: or (2) redirectAction: prefix.

5.8
CVSS
94.7%
EPSS (exploit prob.)
100th
EPSS percentile
2013-07-20
Published

AV:N/AC:M/Au:N/C:P/I:P/A:N

Weaknesses

CWE-20

Affected products

VendorProductAffected versions
apachestruts2.0.0
apachestruts2.0.1
apachestruts2.0.2
apachestruts2.0.3
apachestruts2.0.4
apachestruts2.0.5
apachestruts2.0.6
apachestruts2.0.7
apachestruts2.0.8
apachestruts2.0.9
apachestruts2.0.10
apachestruts2.0.11
apachestruts2.0.11.1
apachestruts2.0.11.2
apachestruts2.0.12
apachestruts2.0.13
apachestruts2.0.14
apachestruts2.1.0
apachestruts2.1.1
apachestruts2.1.2
apachestruts2.1.3
apachestruts2.1.4
apachestruts2.1.5
apachestruts2.1.6
apachestruts2.1.8
apachestruts2.1.8.1
apachestruts2.2.1
apachestruts2.2.1.1
apachestruts2.2.3
apachestruts2.2.3.1
apachestruts2.3.1
apachestruts2.3.1.1
apachestruts2.3.1.2
apachestruts2.3.3
apachestruts2.3.4
apachestruts2.3.4.1
apachestruts2.3.7
apachestruts2.3.8
apachestruts2.3.12
apachestruts2.3.14

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2013-2248