CVE-2020-17530
KEVCRITICAL 9.8EPSS 95.9%
Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected software : Apache Struts 2.0.0 - Struts 2.5.25.
- CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:H - CVSS v2.0
- 7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P - EPSS
- 95.93% chance of exploitation in the next 30 days, 100th percentile
- CISA KEV
- added 2021-11-03
- Nuclei
- critical · CWE-917
- Published
- 2020-12-11
- Updated
- 2025-10-21
Proof-of-concept exploits (19)
- Al1ex/CVE-2020-1753029★ · 2020-12-22
- CyborgSecurity/CVE-2020-175304★ · 2020-12-30
- JordanANDJohn/CVE-2021-31805-POC1★ · 2022-04-18
- Wrin9/CVE-2021-3180537★ · 2022-04-15
- fatkz/CVE-2020-175300★ · 2025-05-14
- fengziHK/CVE-2020-17530-strust2-0617★ · 2020-12-14
- fleabane1/CVE-2021-31805-POC1★ · 2022-04-18
- ka1n4t/CVE-2020-1753064★ · 2020-12-09
- keyuan15/CVE-2020-175300★ · 2023-04-02
- killmonday/CVE-2020-17530-s2-0610★ · 2021-01-24
- lucksec/S2-62poc1★ · 2022-04-15
- nth347/CVE-2020-175300★ · 2023-08-04
- pangyu360es/CVE-2020-175301★ · 2020-12-09
- phil-fly/CVE-2020-175304★ · 2020-12-09
- secpool2000/CVE-2020-175301★ · 2020-12-09
- uzzzval/CVE-2020-175305★ · 2021-01-07
- whale-baby/exploitation-of-vulnerability0★ · 2021-01-18
- wuzuowei/CVE-2020-1753046★ · 2020-12-18
- z92g/CVE-2021-318055★ · 2022-07-23
Nuclei templates (1)
Metasploit modules (1)
Exploit collections (2)
- tzwlhack/Vulnerability/blob/main/Struts2%20s2-061%20Poc%20(CVE-2020-17530).md
- zan8in/afrog/blob/main/pocs/afrog-pocs/CVE/2020/CVE-2020-17530.yaml