← All CVEs

CVE-2013-4212

medium · 6.8

Certain getText methods in the ActionSupport controller in Apache Roller before 5.0.2 allow remote attackers to execute arbitrary OGNL expressions via the first or second parameter, as demonstrated by the pageTitle parameter in the !getPageTitle sub-URL to roller-ui/login.rol, which uses a subclass of UIAction, aka "OGNL Injection."

6.8
CVSS
81.1%
EPSS (exploit prob.)
100th
EPSS percentile
2013-12-07
Published

AV:N/AC:M/Au:N/C:P/I:P/A:P

Weaknesses

CWE-94

Affected products

VendorProductAffected versions
apacheroller<= 5.0.1
apacheroller4.0
apacheroller4.0.1
apacheroller5.0

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2013-4212