XSLTResult in Apache Struts 2.x before 2.3.20.2, 2.3.24.x before 2.3.24.2, and 2.3.28.x before 2.3.28.1 allows remote attackers to execute arbitrary code via the stylesheet location parameter.
https://github.com/advisories/GHSA-pvm9-288c-v5wq
https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-4828
http://www.securitytracker.com/id/1035664