Sploitus

Exploit for Deserialization of Untrusted Data in Apache Struts

githubexploit Β· 2022-10-03

Exploit Code

README5 lines
## https://sploitus.com/exploit?id=03796F43-4063-5445-98DE-0EFDAD93378E
# CVE-2017-9805
CVE-2017-9805 POC

The issue comes from a lack of filtering on the deserialization class used by the REST plugin. Struts uses Xstream with a lot of filtering for deserialization in multiple places, however this filtering was not in place for the REST plugin.