Apache Struts 2.0.0 through Struts 2.5.25 is susceptible to remote code execution because forced OGNL evaluation, when evaluated on raw user input in tag attributes, may allow it.
id: CVE-2020-17530
info:
name: Apache Struts 2.0.0-2.5.25 - Remote Code Execution
author: pikpi
...