← back
CVE-2023-50164observed exploitationCWE-552

Apache Struts: File upload component had a directory traversal vulnerability

67Vexday Risk Score

Prioritize patching. It exploitation observed by VulnCheck and has a public proof of concept.

ssvc Actepss 81%
from disclosure to weapon8 days
Published on NVDDec 7
1st PoC+8d
VulnCheck+55d
exploitation probability
81%top 1% of all CVEs
observed exploitation
yesVulnCheck
8 public exploit(s)
An attacker can manipulate file upload params to enable paths traversal and under some circumstances this can lead to uploading a malicious file which can be used to perform Remote Code Execution. Users are recommended to upgrade to versions Struts 2.5.33 or Struts 6.3.0.2 or greater to fix this issue.
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.