Apache Struts 2.1.x and 2.3.x with the Struts 1 plugin might allow remote code execution via a malicious field value passed in a raw message to the ActionMessage.
Log in to view the POC file snapshot cached by Shenlong Bot
Log in to view