CVE-2013-1966

EPSS 91.1%

Arbitrary code execution in Apache Struts

Published: 5/14/2022Modified: 12/5/2024

Description

Apache Struts 2 before 2.3.14.2 allows remote attackers to execute arbitrary OGNL code via a crafted request that is not properly handled when using the includeParams attribute in the (1) URL or (2) A tag.

Affected packages (2)

References (6)