The MultiPageValidator implementation in Apache Struts 1 1.1 through 1.3.10 allows remote attackers to bypass intended access restrictions via a modified page parameter.
Fix available through Seal Security. No upgrade required, protect your application instantly.
Fix without upgrading