This lab returns verbose error messages that reveal the application is using a vulnerable version of a third-party framework.
To solve the lab, you need to obtain and submit the version number of the framework.
productId parameter from integer β string and observe how the backend handles the error.productId=abc instead of a number.
The error message revealed the application is using:
Apache Struts 2 2.3.31
Submitting this version number solved the lab π.