What happened
The Struts 1 plugin in Apache Struts might allow remote code execution via a malicious field value passed in a raw message to the ActionMessage.
Affected versions
Struts 1: See original advisory Fixed: See vendor advisory.
Why it matters
This source correlation may provide earlier visibility while structured CVE metadata is still being updated.
Detection & mitigation
- Review the original advisory and validate affected versions.
- Apply vendor-provided updates or mitigations when available.
Public PoC references
RepositoryAuthorFirst seenReference
Exploit-DB 44643Apache Struts 2 - Struts 1 Plugin Showcase OGNL Code Execution (Metasploit)Metasploit2018-05-17VerifiedExploit-DB 42324Apache Struts 2.3.x Showcase - Remote Code ExecutionVex Woo2017-07-07VerifiedSploitusStruts2-048 (CVE-2017-9791) PoC tool targeting Struts2 .action endpoints.KitPloit2026-09-04T02:27:13Candidatekitploit.comStruts2-048 (CVE-2017-9791) PoC tool targeting Struts2 .action endpoints.ar2026-09-04T02:27:13CandidateSource timeline
Discovered through CISA Known Exploited VulnerabilitiesView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Record history
Record created from the first normalized source observation.
Metadata and source references refreshed.