← Vulnerability feed

Vulnerability record · CVE-2013-4212 · published 7 December 2013

CVE-2013-4212: Apache Roller OGNL injection in ActionSupport getText methods

Apache · Roller

Apache Roller before 5.0.2 passes attacker-controlled parameters into OGNL expressions inside certain getText methods of the ActionSupport controller, allowing remote code execution. The flaw is reachable through the roller-ui/login.rol endpoint, as shown by the pageTitle parameter in the !getPageTitle sub-URL. It matters because a public exploit exists and the affected component is a web-facing application.

6.8 CVSS 2.0 Medium EPSS 81% · top 0.4% CWE-94 · Code injection
6.8CVSS 2.0 base score
81%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
14References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

Certain getText methods in the ActionSupport controller in Apache Roller before 5.0.2 allow remote attackers to execute arbitrary OGNL expressions via the first or second parameter, as demonstrated by the pageTitle parameter in the !getPageTitle sub-URL to roller-ui/login.rol, which uses a subclass of UIAction, aka "OGNL Injection."

AV:N/AC:M/Au:N/C:P/I:P/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

high priorityRemote code execution with a public exploit and very high EPSS, though the CVSS v2 score is only 6.8 and no KEV listing exists.

What it is

Apache Roller before 5.0.2 passes attacker-controlled parameters into OGNL expressions inside certain getText methods of the ActionSupport controller, allowing remote code execution. The flaw is reachable through the roller-ui/login.rol endpoint, as shown by the pageTitle parameter in the !getPageTitle sub-URL. It matters because a public exploit exists and the affected component is a web-facing application.

Impact

An attacker can execute arbitrary OGNL expressions, which in this context means arbitrary code execution on the Roller server. That gives full control of the application process and its data.

Attack surface

Reached over the network via HTTP requests to roller-ui/login.rol using crafted parameters such as pageTitle. The CVSS vector shows no authentication required (Au:N) but medium access complexity (AC:M); no user interaction is indicated.

Exploitation

Not listed in CISA KEV, but EPSS is very high (0.81, 99.6th percentile) and an Exploit-DB entry is referenced, indicating public exploit code is available.

What to do

  • Upgrade Apache Roller to 5.0.2 or later, which the vendor patch reference addresses.
  • If immediate upgrade is not possible, restrict network access to roller-ui endpoints and login.rol to trusted users.
  • Review and harden any custom UIAction subclasses that pass request parameters into getText or OGNL evaluation.
  • Monitor for and block OGNL expression patterns in request parameters at the WAF or reverse proxy.
  • Confirm no unauthorized changes to the Roller application or host after exposure.

Detection

  • Search web logs for requests to roller-ui/login.rol with unusual pageTitle or other parameter values containing OGNL syntax such as @, #, or method calls.
  • Alert on OGNL-like strings in HTTP query strings or POST bodies reaching Roller.
  • Monitor the Roller process for unexpected child processes or outbound connections.
  • Review application and system logs for errors or stack traces referencing OGNL or getText around suspicious requests.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2013-4212 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2018-17198Apache roller server-side request forgery (ssrf) vulnerabilityServer-side Request Forgery (SSRF) and File Enumeration vulnerability in Apache Roller 5.2.1, 5.2.0 and earlier unsupported versions relies on Java S…EPSS 4.1%9.8CVE-2014-0030Apache roller xml external entity (xxe) vulnerabilityThe XML-RPC protocol support in Apache Roller before 5.0.3 allows attackers to conduct XML External Entity (XXE) attacks via unspecified vectors.EPSS 17%7.5CVE-2021-33580Apache roller uncontrolled resource consumption vulnerabilityUser controlled `request.getHeader("Referer")`, `request.getRequestURL()` and `request.getQueryString()` are used to build and run a regex expression…EPSS 3.3%7.2CVE-2015-0249Apache roller code injection vulnerabilityThe weblog page template in Apache Roller 5.1 through 5.1.1 allows remote authenticated users with admin privileges for a weblog to execute arbitrary…EPSS 4.6%6.8CVE-2012-2380Apache roller cross-site request forgery vulnerabilityMultiple cross-site request forgery (CSRF) vulnerabilities in the admin/editor console in Apache Roller before 5.0.1 allow remote attackers to hijack…EPSS 1.6%6.1CVE-2019-0234Apache roller cross-site scripting vulnerabilityA Reflected Cross-site Scripting (XSS) vulnerability exists in Apache Roller. Roller's Math Comment Authenticator did not property sanitize user inpu…EPSS 3.4%5.4CVE-2024-25090Apache roller improper input validation vulnerabilityInsufficient input validation and sanitation in Profile name & screenname, Bookmark name & description and blogroll name features in all versions of …EPSS 0.75%5.4CVE-2023-37581Apache roller cross-site scripting vulnerabilityInsufficient input validation and sanitation in Weblog Category name, Website About and File Upload features in all versions of Apache Roller on all …EPSS 1.2%

Source: NIST National Vulnerability Database (record CVE-2013-4212), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.