← Vulnerability feed

Vulnerability record · CVE-2013-6430 · published 10 January 2020

CVE-2013-6430: Pivotal software spring framework cross-site scripting vulnerability

Pivotal Software · Spring Framework

The JavaScriptUtils.javaScriptEscape method in web/util/JavaScriptUtils.java in Spring MVC in Spring Framework before 3.2.2 does not properly escape certain characters, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a (1) line separator or (2) paragraph separator Unicode character or (3) left or (4) right angle bracket.

5.4 CVSS 3.1 Medium EPSS 1.8% · top 22.7% CWE-79 · Cross-site scripting
5.4CVSS 3.1 base score, v2 3.5
1.8%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

The JavaScriptUtils.javaScriptEscape method in web/util/JavaScriptUtils.java in Spring MVC in Spring Framework before 3.2.2 does not properly escape certain characters, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a (1) line separator or (2) paragraph separator Unicode character or (3) left or (4) right angle bracket.

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2013-6430 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2014-0225Pivotal software spring framework xml external entity (xxe) vulnerabilityWhen processing user provided XML documents, the Spring Framework 4.0.0 to 4.0.4, 3.0.0 to 3.2.8, and possibly earlier unsupported versions did not d…EPSS 1.7%7.5CVE-2016-5007Pivotal software spring framework permissions and access controls vulnerabilityBoth Spring Security 3.2.x, 4.0.x, 4.1.0 and the Spring Framework 3.2.x, 4.0.x, 4.1.x, 4.2.x rely on URL pattern mappings for authorization and for m…EPSS 2.8%7.5CVE-2016-9878Pivotal software spring framework path traversal vulnerabilityAn issue was discovered in Pivotal Spring Framework before 3.2.18, 4.2.x before 4.2.9, and 4.3.x before 4.3.5. Paths provided to the ResourceServlet …EPSS 5.7%6.8CVE-2013-6429Spring MVC SourceHttpMessageConverter XXE enables file read and CSRFSpring MVC's SourceHttpMessageConverter in Spring Framework before 3.2.5 and 4.0.0.M1 through 4.0.0.RC1 fails to disable external entity resolution w…EPSS 91%analysed5.5CVE-2015-3192Pivotal software spring framework memory buffer overflow vulnerabilityPivotal Spring Framework before 3.2.14 and 4.x before 4.1.7 do not properly process inline DTD declarations when DTD is not entirely disabled, which …EPSS 2.6%5.0CVE-2015-0201Pivotal software spring framework vulnerabilityThe Java SockJS client in Pivotal Spring Framework 4.1.x before 4.1.5 generates predictable session ids, which allows remote attackers to send messag…EPSS 1.9%5.0CVE-2014-3578Pivotal software spring framework path traversal vulnerabilityDirectory traversal vulnerability in Pivotal Spring Framework 3.x before 3.2.9 and 4.0 before 4.0.5 allows remote attackers to read arbitrary files v…EPSS 6.3%5.0CVE-2014-3625Pivotal software spring framework path traversal vulnerabilityDirectory traversal vulnerability in Pivotal Spring Framework 3.0.4 through 3.2.x before 3.2.12, 4.0.x before 4.0.8, and 4.1.x before 4.1.2 allows re…EPSS 10%

Source: NIST National Vulnerability Database (record CVE-2013-6430), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.