An Apache Struts 2.3.30 file upload application, vulnerable to S2-045 (CVE-2017-5638): the Jakarta multipart parser evaluates an OGNL expression placed in the Content-Type header.
Not startedDockercommit 960170ex86_64 · aarch64Secret
Exploit S2-045 (CVE-2017-5638) to run a command on the server.
The brief for this lab lives in its repository.