DEV Community

Discussion on: Understanding Spring4Shell RCE from an engineer’s perspective

Collapse
 
dagnelies profile image
Arnaud Dagnelies • Edited

Strange ...I'm actually surprised your example is vulnerable. I remember toying around with the original exploit example and it only worked if the parameter was anotated with @ModelAttribute, as commented here ...I wonder what the difference is.