Launchpad.net

CVE 2015-0899

The MultiPageValidator implementation in Apache Struts 1 1.1 through 1.3.10 allows remote attackers to bypass intended access restrictions via a modified page parameter.

See the CVE page on Mitre.org for more details.