CVE-2023-50164 Coverage Advisory
ID: 9edc6313-3e20-530f-a300-f9ac32fd2f4f
STIX ID: report--9edc6313-3e20-530f-a300-f9ac32fd2f4f
Feed Name: Zscaler Security Research Blog
Threat Score
This report details an attack chain exploiting CVE-2023-50164 in Apache Struts: an attacker crafts a multipart/form-data POST that uses mismatched parameter names and a path-traversal payload (via an "uploadFileName" field) to evade getCanonicalName checks, enabling upload of a malicious WAR/webshell to a target Tomcat webapps directory and resulting in remote code execution.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
