CVE-2014-7809
Apache Struts 2.0.0 through 2.3.x before 2.3.20 uses predictable <s:token/> values, which allows remote attackers to byp
Apache Struts 2.0.0 through 2.3.x before 2.3.20 uses predictable <s:token/> values, which allows remote attackers to bypass the CSRF protection mechanism.
MEDIUM · CVSS 6.8
EPSS 0.07545
Schedule remediation
- EPSS percentile: top 8% of all CVEs by exploitation likelihood
- Public exploit or PoC is available
Sigma rules0
YARA rules0