S4E just found a critical-severity finding from ruijie rg-uac remote code execution scanner
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Dec 16, 2023

CVE-2013-2248 Scanner

CVE-2013-2248 scanner - Open Redirect vulnerability in Apache Struts

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.3k
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2013-2248
5.8
CVSS

Multiple open redirect vulnerabilities in Apache Struts 2.0.0 through 2.3.15 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in a parameter using the (1) redirect: or (2) redirectAction: prefix.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 22, 2026View on NVD →
Detail

Apache Struts is an open-source web application framework used for developing Java EE web applications. It is widely used by developers due to its scalability, extensibility, and ease of use. The framework was designed to make the development process more efficient and straightforward, providing a large library of pre-built components that developers can use to construct web applications. The framework is widely adopted by many popular websites including LinkedIn, Lockheed Martin, the IRS, and Vodafone.

CVE-2013-2248 is one of the most critical vulnerabilities detected in Apache Struts. This vulnerability allows hackers to conduct open redirect attacks, which can result in phishing attacks and users being redirected to malicious websites. The vulnerability exists in Struts 2.0.0 through 2.3.15 and can be exploited by attackers by injecting malicious code into a parameter in the URL, using either the "redirect:" or "redirectAction:" prefix.

When exploited, this vulnerability can lead to serious consequences, such as users being redirected to phishing sites and their personal information being stolen. Attackers can also use this vulnerability to inject malware into the user's system or even take control of their device. As a result, users can suffer financial loss, identity theft, and many other disturbing consequences.

At s4e.io, we are committed to helping our users stay informed about the latest vulnerabilities and threats that could put their digital assets at risk. With our pro features, users can quickly and easily learn about vulnerabilities in their digital assets and take action to prevent attacks. Our platform offers multiple security features such as web and mobile application scanners, online vulnerability assessment tools, risk management solutions, and much more. By taking advantage of our innovative security solutions, users can stay ahead of security threats and protect their digital assets from cyber-attacks.

 

REFERENCES

Solution Advice

There are several precautions that can be taken to protect against this vulnerability. Some of these include:

  • Keeping your software up-to-date by regularly checking for updates and patches.
  • Using a web application firewall to monitor and block any suspicious traffic.
  • Implementing input validation and sanitization to prevent the injection of malicious code into the URL.
  • Limiting access to sensitive pages and user data.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2013-2248 scanner - Open Redirect vulnerability in Apache Struts | S4E