CVE-2013-7315: The Spring MVC in Spring Framework before 3.2.4 and 4.0.0.M1 through 4.0.0.M2 does not disable external entity resolutio
infovulnerability
security
Summary
Spring Framework versions before 3.2.4 and certain 4.0.0 versions have a vulnerability where XML processing doesn't block external entity resolution, allowing attackers to read files, disrupt service, or perform CSRF attacks (cross-site request forgery, where attackers trick users into performing unwanted actions) through specially crafted XML input. This is classified as an XXE issue (XML External Entity, a type of attack that exploits how XML parsers handle external references).
Vulnerability Details
CVSS Score
6.8
EPSS (30-day exploit probability)
EPSS: 0.5%
Classification
Attack SophisticationModerate
Taxonomy References
CWE (Weakness Type)
Original source: https://nvd.nist.gov/vuln/detail/CVE-2013-7315
First tracked: February 15, 2026 at 08:43 PM
Classified by LLM (prompt v3) · confidence: 95%