Security Research

CVE-2023-50164 Apache Struts: Path Traversal in File Upload to RCE

#Vulnerability Analysis#Code Audit#Web Security
Copper-orange Struts upload path being traversed into Tomcat webapps

Apache Struts’ ActionSupport does not strictly validate upload paths, so changing a single multipart field name lets attackers drop a webshell straight into Tomcat webapps — yet another round of the old path-traversal-to-RCE story hitting Struts in 2023.

Unlock to view this content.