The Struts2 2.3.32 showcase application, vulnerable to S2-048 (CVE-2017-9791): the Struts 1 plugin integration page (Save Gangster) passes the submitted name into an action message key, which is evaluated as an OGNL expression and runs commands.
Not startedDockercommit f634ebax86_64 · aarch64Secret
Exploit S2-048 through the showcase's Struts 1 integration page to run commands and get a shell.
The brief for this lab lives in its repository.