CVE-2013-2134

EXPLOITED

Apache Struts < 2.3.14.3 - Code Injection

Title source: rule

Description

Apache Struts 2 before 2.3.14.3 allows remote attackers to execute arbitrary OGNL code via a request with a crafted action name that is not properly handled during wildcard matching, a different vulnerability than CVE-2013-2135.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Jon Passki · textremotemultiple
https://www.exploit-db.com/exploits/38549

Scores

EPSS 0.9153
EPSS Percentile 99.7%

Details

VulnCheck KEV 2025-10-13
CWE
CWE-94
Status published
Products (3)
apache/struts 2.0.0 - 2.3.14.3
org.apache.struts/struts2-core 2.0.0 - 2.3.14.3Maven
org.apache.struts.xwork/xwork-core 2.0.0 - 2.3.14.3Maven
Published Jul 16, 2013
Tracked Since Feb 18, 2026