Loading
An attacker can manipulate file upload params to enable paths traversal and under some circumstances this can lead to uploading a malicious file which can be used to perform Remote Code Execution. Users are recommended to upgrade to versions Struts 2.5.33 or Struts 6.3.0.2 or greater to fix this issue.
Use CWE-552, Apache vendor hub and Struts product page to widen CVE-2023-50164 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2020-17530, CVE-2021-31805 and CVE-2024-53677 for nearby disclosures in the same product family.