Apache Struts是美国阿帕奇(Apache)基金会的一个开源项目,是一套用于创建企业级Java Web应用的开源MVC框架,主要提供两个版本框架产品,Struts 1和Struts 2。 Apache Struts 2.0.0版本至2.3.37版本、2.5.0版本至2.5.33版本和6.0.0 版本至6.1.0版本在安全漏洞,该漏洞源于缺少XML验证,容易受到XML外部实体注入攻击。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Apache Software Foundation | Apache Struts | 2.0.0< 2.2.1 |
affected |
2.2.1≤ 6.1.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache Struts | 2.0.0 ~ 2.2.1 | - |
|
| Apache Software Foundation | Apache Struts | 2.2.1 ~ 6.1.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | None | https://github.com/Threekiii/Awesome-POC/blob/master/Web%E5%BA%94%E7%94%A8%E6%BC%8F%E6%B4%9E/Apache%20Struts%20S2-069%20XML%20%E5%A4%96%E9%83%A8%E5%AE%9E%E4%BD%93%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E%20CVE-2025-68493.md | POC Details |
| 2 | CVE-2025-68493 | https://github.com/hsltz/CVE-2025-68493 | POC Details |
| 3 | Apache Struts 2.0.0 < 2.2.1 and 2.2.1 <= versions <= 6.1.0 contain an XML external entity injection caused by missing XML validation, letting attackers potentially disclose files or cause denial of service, exploit requires crafted XML input | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2025/CVE-2025-68493.yaml | POC Details |
No public POC found.
Login to generate AI POCNo comments yet