logo

Database

Insecure file upload In org.apache.struts:struts2-core

Description

Unrestricted Upload of File with Dangerous Type in Apache Struts2 A local code execution issue exists in Apache Struts2 when processing malformed XSLT files, which could let a malicious user upload and execute arbitrary files. A patch exists as of version 2.5.22.

Mitigation

Update Impact

Minimal update. May introduce new vulnerabilities or breaking changes.

Ecosystem
Component
Affected version
Patched versions
FLAT-L704V – Vulnerability | Fluid Attacks Database