Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2013-4212

78
FAUCET Score

CVE-2013-4212 describes an OGNL injection vulnerability in Apache Roller versions prior to 5.0.2. Specifically, certain getText methods within the ActionSupport controller allow remote attackers to execute arbitrary OGNL expressions through parameters like pageTitle, as demonstrated in the roller-ui/login.rol sub-URL. This vulnerability carries a CVSS score of 6.8 (medium severity) due to its network-based attack vector, medium attack complexity, and potential for partial compromise of confidentiality, integrity, and availability. While not on the CISA KEV catalog, a Metasploit module exists for this vulnerability, indicating readily available exploit code, though there is minimal community discussion or media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
<= 5.0.1CPE matchmatch criteria
cpe:2.3:a:apache:roller:*:*:*:*:*:*:*:*
4.0CPE matchmatch criteria
cpe:2.3:a:apache:roller:4.0:*:*:*:*:*:*:*
4.0.1CPE matchmatch criteria
cpe:2.3:a:apache:roller:4.0.1:*:*:*:*:*:*:*
5.0CPE matchmatch criteria
cpe:2.3:a:apache:roller:5.0:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

6.8MEDIUM

AV:N/AC:M/Au:N/C:P/I:P/A:P

Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
Access Vector
NETWORK
Access Complexity
MEDIUM
Authentication
NONE
Exploitability Score
8.6
Impact Score
6.4
CvssVersion
2.0

Exploit Intelligence

EPSS Score
81.07%
Probability of exploitation in next 30 days
EPSS Percentile
99.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
Metasploit: Apache Roller OGNL Injection · Oct 31, 2013
ExploitDB: EDB-29859 · Nov 27, 2013
This CVE's current EPSS score of 0.8107 is in the 100th percentile among its peer group of 19,955 CVEs.

Social Chatter

No social media mentions found for this CVE.

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.

References

rollerweblogger.org / project/entry/apache_roller_5_0_2
Patch
secunia.com / advisories/55862
Vendor Advisory
secunia.com / advisories/55877
Vendor Advisory
security.coverity.com / advisory/2013/Oct/remote-code-execution-in-apache-roller-via-ognl-injection.html
exchange.xforce.ibmcloud.com / vulnerabilities/89239
exploit-db.com / exploits/29859
Exploit
osvdb.org / 100342