The ParametersInterceptor in Apache Struts before 2.3.16.2 allows remote attackers to "manipulate" the ClassLoader via the class parameter, which is passed to the getClass method.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.932
EPSS Ranking 99.8%