Feed/CVE-2023-50164
CVE-2023-50164CRITICALCVSS 9.8

CVE-2023-50164

Published Dec 7, 2023·Updated Jun 17, 2026

NVD Description

An attacker can manipulate file upload params to enable paths traversal and under some circumstances this can lead to uploading a malicious file which can be used to perform Remote Code Execution. Users are recommended to upgrade to versions Struts 2.5.33 or Struts 6.3.0.2 or greater to fix this issue.

Public Exploits & PoCs12 found

PoC: cve-2023-50164-poc

Proof of Concept for Path Traversal in Apache Struts ("CVE-2023-50164")

1

PoC: CVE-2023-50164-HTB-strutted

Proof-of-concept for CVE-2023-50164 (Apache Struts 2), originally by jakabakos and adapted for the HTB Strutted lab environment. For educational use only.

PoC: cve-2023-50164-poc

Proof of Concept for Path Traversal in Apache Struts ("CVE-2023-50164")

PoC: cve-2023-50164-poc

Proof of Concept for Path Traversal in Apache Struts ("CVE-2023-50164")

PoC: cve-2023-50164-poc

Proof of Concept for Path Traversal in Apache Struts ("CVE-2023-50164")

PoC: CVE-2024-10924-Wordpress-Docker

Vulnerable docker container for Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 – 9.1.1.1 – Authentication Bypass CVE-2023-50164

PoC: CVE-2023-50164-PoC

CVE-2023-50164 PoC Application & Exploit script

PoC: CVE-2023-50164Analysis-

CVE-2023-50164 An attacker can manipulate file upload params to enable paths traversal and under some circumstances this can lead to uploading a malicious file which can be used to perform Remote Code Execution. Users are recommended to upgrade to versions Struts 2.5.33 or Struts 6.3.0.2 or greater to fix this issue.

PoC: CVE-2023-50164-PoC

CVE-2023-50164 (Apache Struts path traversal to RCE vulnerability) - Proof of Concept

PoC: CVE-2023-50164-ApacheStruts2-Docker

Vulnerable docker container for Apache Struts 2 RCE CVE-2023-50164

PoC: CVE-2023-50164

A scanning utility and PoC for CVE-2023-50164

PoC: CVE-2023-50164-Apache-Struts-RCE

A critical security vulnerability, identified as CVE-2023-50164 (CVE: 9.8) was found in Apache Struts, allowing attackers to manipulate file upload parameters that can potentially lead to unauthorized path traversal and remote code execution (RCE).

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free