peter bassill · operator
$ cve CVE-2013-4212 JSON

CVE-2013-4212 EXPLOIT

6.8
MEDIUM · CVSS 2.0 · EPSS 81.1% (pctl 100)

Patch early

A public exploit exists.

Description

Certain getText methods in the ActionSupport controller in Apache Roller before 5.0.2 allow remote attackers to execute arbitrary OGNL expressions via the first or second parameter, as demonstrated by the pageTitle parameter in the !getPageTitle sub-URL to roller-ui/login.rol, which uses a subclass of UIAction, aka "OGNL Injection."

Scoring

CVSS6.8 (MEDIUM, v2.0)
VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
EPSS81.07% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-94
On CISA KEVno
Public exploityes
Published2013-12-07
Last modified2026-06-16

Affected (1)

VendorProduct
apacheroller

Public exploits

SourceTitleDate
exploit-dbApache Roller - OGNL Injection (Metasploit)2013-11-27

References

→ the Explorer  ·  watch your stack  ·  NVD