CVE-2013-1966 is a critical remote code execution vulnerability affecting Apache Struts 2 versions prior to 2.3.14.2. Attackers can exploit this flaw by injecting crafted OGNL code through the includeParams attribute in URL or A tags, leading to arbitrary code execution on the vulnerable server. With a CVSS score of 9.3 and an EPSS score indicating high exploitability, this vulnerability poses a severe risk, allowing for complete compromise of confidentiality, integrity, and availability. Exploit code, including a Metasploit module, is publicly available, and the vulnerability has garnered significant community discussion and media attention, with reports of active targeting by attackers.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.0.0, < 2.3.14.1CPE matchmatch criteria | cpe:2.3:a:apache:struts:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:C/I:C/A:C
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.