
Critical Vulnerability Discovered in Struts 2 Framework
WebSecurity
A critical vulnerability has been discovered in Struts 2, a Java framework used for web application development. This flaw allows for remote code execution (RCE) and has been exploited to perform an SQL injection into a MySQL database, thereby transforming the attack into a persistent storage threat. Additionally, third-party Python libraries have been compromised, exacerbating the situation. The impacts include the compromise of sensitive data and loss of control over affected systems.