CVE-2014-0094

EPSS 93.1%

ClassLoader manipulation in Apache Struts

Published: 5/14/2022Modified: 12/6/2024

Description

The ParametersInterceptor in Apache Struts before 2.3.16.2 allows remote attackers to "manipulate" the ClassLoader via the class parameter, which is passed to the getClass method.

Affected packages (2)

References (12)