Apache Struts CVE-2018-11776 Input Validation Bypass Vulnerability

description-logoDescription

It is possible to perform a RCE attack whennamespacevalue isn't set for a result defined in underlying xml configurations and in same time, its upper action(s) configurations have no or wildcardnamespace. Same possibility when usingurltag which doesnt havevalueandactionset and in same time, its upper action(s) configurations have no or wildcardnamespace.

affected-products-logoAffected Applications

Apache Struts

CVE References

CVE-2018-11776