A Struts2 2.5.10 application, vulnerable to S2-053 (CVE-2017-12611): a Freemarker template uses an unsafe expression on a user-controlled value (redirectUri), so a submitted %{...} is evaluated as OGNL and runs commands.
Not startedDockercommit 0b5b280x86_64 · aarch64Secret
Exploit S2-053 through the form's field to run commands on the server and get a shell.
The brief for this lab lives in its repository.