CVE-2012-1592: Malicious File Upload
Published Dec 5, 2019
·Updated
A local code execution issue exists in Apache Struts2 when processing malformed XSLT files, which could let a malicious user upload and execute arbitrary files.
Affected Software
2 affected components
Apache struts=2.0.0
debian/libstruts1.2-java
Event History
Dec 5, 2019
CVE Published
via MITRE·08:57 PM
Data Sourced
via MITRE·08:57 PM
DescriptionWeakness
Data Sourced
09:15 PM
DescriptionSeverityWeaknessAffected Software
Feb 18, 2026
Data Sourced
via Debian·01:11 AM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2012-1592?
CVE-2012-1592 has a moderate severity level due to the potential for local code execution.
2
How do I fix CVE-2012-1592?
To fix CVE-2012-1592, upgrade to a patched version of Apache Struts that resolves the vulnerability.
3
Who is affected by CVE-2012-1592?
CVE-2012-1592 affects users of Apache Struts version 2.0.0 and some versions of libstruts1.2-java.
4
What type of vulnerability is CVE-2012-1592?
CVE-2012-1592 is classified as a local code execution vulnerability.
5
Can CVE-2012-1592 be exploited remotely?
CVE-2012-1592 requires local access to exploit, thus it is not a remote vulnerability.