Talk-a-Blog: Apache Struts2 CVE-2023-50164, File Upload Vulnerability Analysis

Dec 12, 2023

1 min read

In order to see CVE-2023-50164 in the wild, I expect that in the coming weeks, we will see research into vendor and product specific implementations leveraging Apache Struts2 in order to determine exactly what path must be traversed to in order to drop a web shell so that it can be called remotely through a public interface over the defined routes.

Sharing is caring!