logo

CVE-2023-50164 Coverage Advisory

ID: 9edc6313-3e20-530f-a300-f9ac32fd2f4f

STIX ID: report--9edc6313-3e20-530f-a300-f9ac32fd2f4f

Feed Name: Zscaler Security Research Blog

Threat Score
80/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

This report details an attack chain exploiting CVE-2023-50164 in Apache Struts: an attacker crafts a multipart/form-data POST that uses mismatched parameter names and a path-traversal payload (via an "uploadFileName" field) to evade getCanonicalName checks, enabling upload of a malicious WAR/webshell to a target Tomcat webapps directory and resulting in remote code execution.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.