Description
A possible Remote Code Execution attack when using an unintentional expression in Freemarker tag instead of string literals.
Remediation
Upgrade to Struts 2.5.12 or Struts 2.3.34
References
Related Vulnerabilities
MyBB CVE-2006-0218 Vulnerability (CVE-2006-0218)
ReviveAdserver Permissions, Privileges, and Access Controls Vulnerability (CVE-2015-7371)
phpMyAdmin Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2016-5739)
Liferay DXP Incorrect Default Permissions Vulnerability (CVE-2021-38268)