The fact
Attackers can execute JavaScript code in the context of the targeted site.
Developers must update their frameworks to prevent compromises.
Click the link to read an article on the topic:
Why it matters
Apache Struts est largement utilisé dans les applications web d'entreprises. Une faille XSS peut permettre des attaques de phishing ou le vol de données sensibles.