CVE-2015-8813

HIGH EXPLOITED NUCLEI

Umbraco < 7.3.8 - SSRF

Title source: rule

Description

The Page_Load function in Umbraco.Web/umbraco.presentation/umbraco/dashboard/FeedProxy.aspx.cs in Umbraco before 7.4.0 allows remote attackers to conduct server-side request forgery (SSRF) attacks via the url parameter.

Nuclei Templates (1)

Umbraco <7.4.0- Server-Side Request Forgery
HIGHby emadshanab

Scores

CVSS v3 8.2
EPSS 0.8280
EPSS Percentile 99.2%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:H/A:N

Details

VulnCheck KEV 2024-09-19
CWE
CWE-918
Status published
Products (2)
nuget/Umbraco.CMS 0 - 7.4.0NuGet
umbraco/umbraco < 7.3.8
Published Mar 03, 2017
Tracked Since Feb 18, 2026