CVE-2013-1915

high
Published 2013-04-25 · Modified 2026-04-29
CVSS v3
VIR risk
7.5

Description

ModSecurity before 2.7.3 allows remote attackers to read arbitrary files, send HTTP requests to intranet servers, or cause a denial of service (CPU and memory consumption) via an XML external entity declaration in conjunction with an entity reference, aka an XML External Entity (XXE) vulnerability.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

No vendor mitigations ingested yet for this CVE. The mitigation-content worker queues fetches as references arrive — check back in a few minutes, or see the references list below.

OS impact

OSVersionStatusFixed in
suse suse11.4affected
suse suse12.2affected
suse suse12.3affected
fedora fedora17affected
fedora fedora18affected
fedora fedora19affected
debian debian6.0affected
debian debian7.0affected
debian debianbookwormfixed2.6.6-6
debian debianbullseyefixed2.6.6-6
debian debianforkyfixed2.6.6-6
debian debiansidfixed2.6.6-6
debian debiantrixiefixed2.6.6-6

Application impact

VendorProductVersionsFixed
trustwavemodsecurity{"endExcluding":"2.7.3"}2.7.3

References

CWEs

CWE-611

💬 Discuss CVE-2013-1915 on VIR Community →

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.