CVE-2013-1915: Debian Linux
High severity, CVSS 7.5. EPSS: 4.2% chance of exploitation in the next 30 days.
ModSecurity before 2.7.3 allows remote attackers to read arbitrary files, send HTTP requests to intranet servers, or cause a denial of service (CPU and memory consumption) via an XML external entity declaration in conjunction with an entity reference, aka an XML External Entity (XXE) vulnerability.
Affected products
- Debian Debian Linux: version 6.0 only; version 7.0 only
- Fedoraproject Fedora: version 17 only; version 18 only; version 19 only
- Opensuse Opensuse: version 11.4 only; version 12.2 only; version 12.3 only
- Trustwave Modsecurity: before 2.7.3 (fixed in 2.7.3)
Published 2013-04-25. Last modified 2026-06-16.