#VU28582 Improper input validation in Apache Struts - CVE-2016-1181
Published: June 4, 2020 / Updated: December 29, 2025
Apache Struts
Apache Foundation
Description
The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.
The vulnerability exists due to improper input validation in ActionServlet.java when handling multithreaded access to an ActionForm instance. A remote non-authenticated attacker can exploit this vulnerability to execute arbitrary code.