{"id":"CVE-2013-4310","aliases":[],"url":"https://o3.security/vulnerability/CVE-2013-4310","summary":"Apache Struts 2.0.0 through 2.3.15.1 allows remote attackers to bypass access controls via a crafted action: prefix.","details":"Apache Struts 2.0.0 through 2.3.15.1 allows remote attackers to bypass access controls via a crafted action: prefix.","published":"2013-09-30T21:55:09.487","modified":"2026-06-16T23:57:00.163","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[],"fix":null,"references":[{"type":"FIX","url":"http://archives.neohapsis.com/archives/bugtraq/2013-09/0107.html"},{"type":"WEB","url":"http://archives.neohapsis.com/archives/bugtraq/2013-10/0083.html"},{"type":"ADVISORY","url":"http://secunia.com/advisories/54919"},{"type":"WEB","url":"http://secunia.com/advisories/56483"},{"type":"WEB","url":"http://secunia.com/advisories/56492"},{"type":"FIX","url":"http://struts.apache.org/release/2.3.x/docs/s2-018.html"},{"type":"WEB","url":"http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html"},{"type":"WEB","url":"http://www.securityfocus.com/bid/64758"},{"type":"WEB","url":"http://www.securitytracker.com/id/1029077"},{"type":"FIX","url":"http://archives.neohapsis.com/archives/bugtraq/2013-09/0107.html"},{"type":"WEB","url":"http://archives.neohapsis.com/archives/bugtraq/2013-10/0083.html"},{"type":"ADVISORY","url":"http://secunia.com/advisories/54919"},{"type":"WEB","url":"http://secunia.com/advisories/56483"},{"type":"WEB","url":"http://secunia.com/advisories/56492"},{"type":"FIX","url":"http://struts.apache.org/release/2.3.x/docs/s2-018.html"},{"type":"WEB","url":"http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html"},{"type":"WEB","url":"http://www.securityfocus.com/bid/64758"},{"type":"WEB","url":"http://www.securitytracker.com/id/1029077"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-06-16T23:57:00.163"}}