Apache Struts 2.0.0-2.3.16.1 - Remote Code Execution via Class Parameter Manipulation
The ParametersInterceptor in Apache Struts before 2.3.16.2 allows remote attackers to "manipulate" the ClassLoader via the class parameter, which is passed to the getClass method.