Lucene search

K
prionPRIOn knowledge basePRION:CVE-2023-50164
HistoryDec 07, 2023 - 9:15 a.m.

Design/Logic Flaw

2023-12-0709:15:00
PRIOn knowledge base
www.prio-n.com
8
file upload manipulation
paths traversal
malicious file
remote code execution
struts 2.5.33
struts 6.3.0.2
upgrade
nvd

7.3 High

AI Score

Confidence

Low

0.09 Low

EPSS

Percentile

94.7%

An attacker can manipulate file upload params to enable paths traversal and under some circumstances this can lead to uploading a malicious file which can be used to perform Remote Code Execution.
Users are recommended to upgrade to versions Struts 2.5.33 or Struts 6.3.0.2 or greater toย fix this issue.