Looking for the vulnerability index of Invicti's legacy products?
Apache Struts Path traversal (S2-067/CVE-2024-53677, S2-066/CVE-2023-50164) - Vulnerability Database

Apache Struts Path traversal (S2-067/CVE-2024-53677, S2-066/CVE-2023-50164)

Description

The file upload mechanism in Apache Struts contains a vulnerability. An attacker can exploit this by manipulating file upload parameters to perform path traversal, potentially allowing the upload of a malicious file. Under certain conditions, this can lead to Remote Code Execution (RCE)

Remediation

Upgrade at least to Struts 6.4.0 (or the latest version) and migrate to the new file upload mechanism.

Related Vulnerabilities