Apache Struts CVE-2023-50164 Remote Code Execution Vulnerability
Description
Path traversal via manipulated file-upload parameters allows remote code execution in Apache Struts versions before 2.5.33 or 6.3.0.2.
Outbreak Alert
FortiGuard Labs has detected on-going exploit attempts targeting a recently patched Apache Struts 2 vulnerability. Attackers can manipulate file upload parameters to enable path traversal, potentially leading to malicious file upload. This may result in Remote Code Execution, allowing attackers to run arbitrary code, steal data, or compromise entire systems.
Affected Applications
Apache Struts