A Struts2 2.5.25 application, vulnerable to S2-061 (CVE-2020-17530): the page sets a tag attribute from the id parameter with %{...}, forcing a second OGNL evaluation of user input; a payload that sidesteps the S2-059 sandbox runs commands.
Not startedDockercommit eeaf8a1x86_64 · aarch64Secret
Exploit S2-061 through the id parameter to run commands on the Struts2 server and get a shell.
The brief for this lab lives in its repository.