Apache Struts CVE-2018-11776 Input Validation Bypass Vulnerability
Description
It is possible to perform a RCE attack whennamespacevalue isn't set for a result defined in underlying xml configurations and in same time, its upper action(s) configurations have no or wildcardnamespace. Same possibility when usingurltag which doesnt havevalueandactionset and in same time, its upper action(s) configurations have no or wildcardnamespace.
Affected Applications
Apache Struts